5.3

CVSS4.0

CVE-2025-7137 - SourceCodester Best Salon Management System schedule-staff.php sql injection

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/schedule-staff.php. The manipulation of the argument staff_id leads to sql injection. It is possible to initiate the attack remotely. The…

πŸ“… Published: July 7, 2025, 5:02 p.m. πŸ”„ Last Modified: July 9, 2025, 3:27 p.m.

8.7

CVSS4.0

CVE-2025-53530 - WeGIA allows Uncontrolled Resource Consumption via the errorstr parameter

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the errorstr parameter. Tests confirmed that the server processes URLs up to 8,1…

πŸ“… Published: July 7, 2025, 5 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

9.8

CVSS3.1

CVE-2025-53529 - WeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter)

WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properly sanitized or validated before being used in a SQL query, allowing an unauthenticated attacker to …

πŸ“… Published: July 7, 2025, 4:51 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

8.3

CVSS4.0

CVE-2025-53527 - WeGIA allows Time-Based Blind SQL Injection in the relatorio_geracao.php endpoint

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or fu…

πŸ“… Published: July 7, 2025, 4:47 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

6.7

CVSS3.1

CVE-2025-1351 - IBM Storage Virtualize privilege escalation

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.

πŸ“… Published: July 7, 2025, 4:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

2

CVSS4.0

CVE-2025-53526 - WeGIA allows Stored XSS attacks in novo_memorando.php

WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php. After the memo was submitted, the vulnerability was confirmed by accessing listar_memorandos_antigos.php. Upon loading this page, the injected script was executed in the browser.…

πŸ“… Published: July 7, 2025, 4:36 p.m. πŸ”„ Last Modified: July 10, 2025, 9:17 p.m.

6.9

CVSS4.0

CVE-2025-7136 - Campcodes Online Recruitment Management System view_vacancy.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affected is an unknown function of the file /admin/view_vacancy.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The expl…

πŸ“… Published: July 7, 2025, 4:32 p.m. πŸ”„ Last Modified: July 13, 2025, 9:47 p.m.

2

CVSS4.0

CVE-2025-53525 - WebGia allows Cross-Site Scripting (XSS) in profile_familiar.php via the id_dependente parameter

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the profile_familiar.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the id_dependente parameter. This vulnerability i…

πŸ“… Published: July 7, 2025, 4:30 p.m. πŸ”„ Last Modified: July 10, 2025, 9:17 p.m.

5.4

CVSS3.1

CVE-2025-53497 - Stored XSS in RelatedArticles

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 7, 2025, 4:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-53377 - WebGia allows Cross-Site Scripting (XSS) in cadastro_dependente_pessoa_nova.php via the id_funciona…

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the cadastro_dependente_pessoa_nova.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the id_funcionario parameter. This…

πŸ“… Published: July 7, 2025, 4:19 p.m. πŸ”„ Last Modified: July 10, 2025, 2:56 p.m.
Total resulsts: 349182
Page 4762 of 34,919
Β« previous page Β» next page
Filters