6.9

CVSS4.0

CVE-2025-7130 - Campcodes Payroll Management System ajax.php sql injection

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_payroll. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploi…

📅 Published: July 7, 2025, 1:32 p.m. 🔄 Last Modified: July 8, 2025, 6:28 p.m.

6.9

CVSS4.0

CVE-2025-7129 - Campcodes Payroll Management System ajax.php sql injection

A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_employee_attendance_single. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotel…

📅 Published: July 7, 2025, 1:02 p.m. 🔄 Last Modified: July 8, 2025, 6:28 p.m.

6.9

CVSS4.0

CVE-2025-7128 - Campcodes Payroll Management System ajax.php sql injection

A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=calculate_payroll. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit…

📅 Published: July 7, 2025, 12:32 p.m. 🔄 Last Modified: July 8, 2025, 6:28 p.m.

7.5

CVSS3.0

CVE-2025-6209 - Arbitrary File Read through Path Traversal in run-llama/llama_index

A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulnerability allows an attacker to manipulate the `image_path` input to read arbitrary files on the server, including sensiti…

📅 Published: July 7, 2025, 12:21 p.m. 🔄 Last Modified: July 30, 2025, 8:01 p.m.

5.1

CVSS4.0

CVE-2025-7127 - itsourcecode Employee Management System changepassword.php sql injection

A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System up to 1.0. This affects an unknown part of the file /admin/changepassword.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to initiate the attack remot…

📅 Published: July 7, 2025, 12:02 p.m. 🔄 Last Modified: July 8, 2025, 6:29 p.m.

5.3

CVSS4.0

CVE-2025-7126 - itsourcecode Employee Management System adminprofile.php sql injection

A vulnerability, which was classified as critical, has been found in itsourcecode Employee Management System up to 1.0. Affected by this issue is some unknown functionality of the file /admin/adminprofile.php. The manipulation of the argument AdminName leads to sql injection. The attack may be laun…

📅 Published: July 7, 2025, 11:32 a.m. 🔄 Last Modified: July 8, 2025, 6:29 p.m.

5.3

CVSS4.0

CVE-2025-7125 - itsourcecode Employee Management System editempeducation.php sql injection

A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/editempeducation.php. The manipulation of the argument coursepg leads to sql injection. The attack can be launched rem…

📅 Published: July 7, 2025, 11:02 a.m. 🔄 Last Modified: July 8, 2025, 6:29 p.m.

5.3

CVSS4.0

CVE-2025-7124 - code-projects Online Note Sharing Profile Image userprofile.php unrestricted upload

A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Image Handler. The manipulation of the argument image leads to unrestricted upload. It is possible to launc…

📅 Published: July 7, 2025, 10:32 a.m. 🔄 Last Modified: July 8, 2025, 6:29 p.m.

5.1

CVSS4.0

CVE-2025-7123 - Campcodes Complaint Management System complaint-details.php sql injection

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/complaint-details.php. The manipulation of the argument cid/uid leads to sql injection. The attack may be initiated remotely. The expl…

📅 Published: July 7, 2025, 10:02 a.m. 🔄 Last Modified: July 8, 2025, 6:29 p.m.

5.4

CVSS3.1

CVE-2025-3467 - XSS Vulnerability in langgenius/dify

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the mo…

📅 Published: July 7, 2025, 9:56 a.m. 🔄 Last Modified: July 13, 2025, 9:47 p.m.
Total resulsts: 349182
Page 4767 of 34,919
« previous page » next page
Filters