6.9

CVSS4.0

CVE-2025-7458 - SQLite integer overflow in key info allocation may lead to information disclosure.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a laโ€ฆ

๐Ÿ“… Published: July 29, 2025, 12:43 p.m. ๐Ÿ”„ Last Modified: Aug. 11, 2025, 7:11 p.m.

5.4

CVSS3.1

CVE-2025-6060 - XSS in DECE Software's Geodi

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before GEODI Setup 9.0.146.

๐Ÿ“… Published: July 29, 2025, 12:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-41241 - Denial-of-service vulnerability

VMware vCenter contains a denial-of-service vulnerability.ย A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.

๐Ÿ“… Published: July 29, 2025, 12:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-6175 - CRLF Injection in DECE Software's Geodi

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting.This issue affects Geodi: before GEODI Setup 9.0.146.

๐Ÿ“… Published: July 29, 2025, 12:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-40686 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'employeeid' parameter in/detailview.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 8:59 p.m.

4.8

CVSS4.0

CVE-2025-40685 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searcstate' parameter in/state.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 8:59 p.m.

4.8

CVSS4.0

CVE-2025-40684 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searccountry' parameter in/country.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 8:59 p.m.

4.8

CVSS4.0

CVE-2025-40683 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searccity' parameter in /city.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 8:59 p.m.

8.7

CVSS4.0

CVE-2025-40682 - SQL injection vulnerability in Human Resource Management System

SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the โ€œcityโ€ and โ€œstateโ€ parameters in the /controller/ccity.php endpoint.

๐Ÿ“… Published: July 29, 2025, 12:10 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 8:59 p.m.

6.4

CVSS3.1

CVE-2025-5587 - Appzend <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Pโ€ฆ

The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜progressbarLayoutโ€™ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level accesโ€ฆ

๐Ÿ“… Published: July 29, 2025, 11:19 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:15 a.m.
Total resulsts: 349182
Page 4478 of 34,919
ยซ previous page ยป next page
Filters