6.9

CVSS4.0

CVE-2025-7455 - Campcodes Online Movie Theater Seat Reservation System manage_reserve.php sql injection

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_reserve.php. The manipulation of the argument mid leads to sql injection. The attack can be launched remotel…

πŸ“… Published: July 11, 2025, 7:32 p.m. πŸ”„ Last Modified: July 16, 2025, 2:59 p.m.

6.9

CVSS4.0

CVE-2025-7454 - Campcodes Online Movie Theater Seat Reservation System manage_theater.php sql injection

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an unknown function of the file /admin/manage_theater.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The e…

πŸ“… Published: July 11, 2025, 7:02 p.m. πŸ”„ Last Modified: July 16, 2025, 2:59 p.m.

10

CVSS4.0

CVE-2025-7503 -

An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is enabled by default and is not disclosed or configurable via the device’s web interface or user manual. An attacker with ne…

πŸ“… Published: July 11, 2025, 6:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-3631 - IBM MQ denial of service

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

πŸ“… Published: July 11, 2025, 6:37 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:35 a.m.

6.3

CVSS4.0

CVE-2025-7453 - saltbo zpan JSON Web Token token.go NewToken hard-coded password

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipulation with the input 123 leads to use of hard-coded passwor…

πŸ“… Published: July 11, 2025, 6:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-30403 -

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

πŸ“… Published: July 11, 2025, 6:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-30402 -

A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f

πŸ“… Published: July 11, 2025, 5:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-53642 - haxcms-nodejs and haxcms-php Improperly Terminate Sessions

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.

πŸ“… Published: July 11, 2025, 5:33 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:52 p.m.

5.3

CVSS4.0

CVE-2025-7452 - kone-net go-chat Endpoint file_controller.go GetFile path traversal

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the function GetFile of the file go-chat/api/v1/file_controller.go of the component Endpoint. The manipulation of the argument fileName leads to…

πŸ“… Published: July 11, 2025, 5:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-53641 - Postiz allows header mutation in middleware facilitates resulting in SSRF

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized ou…

πŸ“… Published: July 11, 2025, 5:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4670 of 34,919
Β« previous page Β» next page
Filters