7.8

CVSS3.1

CVE-2024-46992 - Electron ASAR Integrity bypass by just modifying the content

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass. This only impacts apps that have the emb…

πŸ“… Published: July 1, 2025, 1:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.7

CVSS3.1

CVE-2025-53095 - Sunshine application-wide CSRF in the UI leads to command injection as Administrator

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can t…

πŸ“… Published: July 1, 2025, 1:33 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 1:44 p.m.

5.4

CVSS3.1

CVE-2025-53096 - Sunshine clickjacking in the UI leads to unauthorized actions being performed

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If…

πŸ“… Published: July 1, 2025, 1:33 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 2:28 p.m.

6.9

CVSS4.0

CVE-2025-6938 - code-projects Simple Pizza Ordering System editcus.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: July 1, 2025, 1:32 a.m. πŸ”„ Last Modified: July 7, 2025, 2:41 p.m.

8.2

CVSS4.0

CVE-2025-53003 - Janssen Config API returns results without scope verification

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts …

πŸ“… Published: July 1, 2025, 1:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-2141 - IBM System Storage Virtualization Engine TS7700 cross-site scripting

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

πŸ“… Published: July 1, 2025, 1:01 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:30 p.m.

5.4

CVSS3.1

CVE-2025-36056 - IBM System Storage Virtualization Engine TS7700 cross-site scripting

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

πŸ“… Published: July 1, 2025, 1 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:31 p.m.

8.9

CVSS4.0

CVE-2025-53005 - Dataease PostgreSQL Data Source JDBC Connection Parameters Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has b…

πŸ“… Published: July 1, 2025, 12:33 a.m. πŸ”„ Last Modified: July 16, 2025, 2:43 p.m.

6.9

CVSS4.0

CVE-2025-6937 - code-projects Simple Pizza Ordering System large.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /large.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been discl…

πŸ“… Published: July 1, 2025, 12:32 a.m. πŸ”„ Last Modified: July 9, 2025, 5:36 p.m.

6.9

CVSS4.0

CVE-2025-6936 - code-projects Simple Pizza Ordering System addpro.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /addpro.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been dis…

πŸ“… Published: July 1, 2025, 12:02 a.m. πŸ”„ Last Modified: July 7, 2025, 2:45 p.m.
Total resulsts: 349182
Page 4830 of 34,919
Β« previous page Β» next page
Filters