5.8

CVSS3.1

CVE-2025-24485 -

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

πŸ“… Published: July 28, 2025, 1:36 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

4.8

CVSS4.0

CVE-2025-8275 - bsc Peru Cocktails App bsc.devy.peru_cocktails AndroidManifest.xml improper export of android appli…

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails. The manipulation leads to improper export of android applic…

πŸ“… Published: July 28, 2025, 12:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8274 - Campcodes Online Recruitment Management System ajax.php sql injection

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack can b…

πŸ“… Published: July 28, 2025, 11:32 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 5:13 p.m.

8.8

CVSS3.1

CVE-2025-5997 - Privilege Escalation in Beamsec PhishPro

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse.This issue affects PhishPro: before 7.5.4.2.

πŸ“… Published: July 28, 2025, 11:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-6918 - SQLi in Ncvav's Virtual PBX Software

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.

πŸ“… Published: July 28, 2025, 11:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8273 - code-projects Exam Form Submission update_s8.php sql injection

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s8.php. The manipulation of the argument credits leads to sql injection. It is possible to launch the attack remotely. The exploit has been disc…

πŸ“… Published: July 28, 2025, 11:02 a.m. πŸ”„ Last Modified: July 30, 2025, 6:01 p.m.

6.9

CVSS4.0

CVE-2025-8272 - code-projects Exam Form Submission update_fst.php sql injection

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/update_fst.php. The manipulation of the argument credits leads to sql injection. The attack may be initiated remotely. The exploit has be…

πŸ“… Published: July 28, 2025, 10:32 a.m. πŸ”„ Last Modified: July 30, 2025, 6:01 p.m.

4.8

CVSS4.0

CVE-2025-40730 - HTML injection in Vox Media's Chorus CMS

HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to p…

πŸ“… Published: July 28, 2025, 10:28 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8271 - code-projects Exam Form Submission delete_s3.php sql injection

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been dis…

πŸ“… Published: July 28, 2025, 10:02 a.m. πŸ”„ Last Modified: July 30, 2025, 6:01 p.m.

6.9

CVSS4.0

CVE-2025-8270 - code-projects Exam Form Submission delete_s2.php sql injection

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s2.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been di…

πŸ“… Published: July 28, 2025, 9:32 a.m. πŸ”„ Last Modified: July 30, 2025, 6:01 p.m.
Total resulsts: 349182
Page 4487 of 34,919
Β« previous page Β» next page
Filters