6.9

CVSS4.0

CVE-2025-6357 - code-projects Simple Pizza Ordering System paymentportal.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:10 p.m.

6.9

CVSS4.0

CVE-2025-6356 - code-projects Simple Pizza Ordering System addmem.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /addmem.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:17 p.m.

2.7

CVSS4.0

CVE-2025-52484 - RISC Zero zkVM Underconstrained Vulnerability

RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a malicious prover. The …

πŸ“… Published: June 20, 2025, 5:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-2443 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

πŸ“… Published: June 20, 2025, 5:12 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:50 p.m.

8.5

CVSS3.1

CVE-2025-5121 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

πŸ“… Published: June 20, 2025, 5:12 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-6355 - SourceCodester Online Hotel Reservation System execeditroom.php sql injection

A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exp…

πŸ“… Published: June 20, 2025, 5 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 3:19 p.m.

10

CVSS3.1

CVE-2025-49132 - Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it co…

πŸ“… Published: June 20, 2025, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-48059 - PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion

PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criteria versions 6.3.0 to before 6.7.2 and com.powsybl:powsybl-contingency-api versions 5.0.0 to before 6.3.0, there is a a potential polynomial Regular Expression Denial of Service (R…

πŸ“… Published: June 20, 2025, 4:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-6354 - code-projects Online Shoe Store customer_signup.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/customer_signup.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotel…

πŸ“… Published: June 20, 2025, 4:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:30 p.m.

5.1

CVSS4.0

CVE-2025-6353 - code-projects Responsive Blog search.php cross site scripting

A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument keyword leads to cross site scripting. The attack can be launched remotely. The exploit has …

πŸ“… Published: June 20, 2025, 4:31 p.m. πŸ”„ Last Modified: July 11, 2025, 12:20 p.m.
Total resulsts: 348415
Page 4855 of 34,842
Β« previous page Β» next page
Filters