5.3

CVSS4.0

CVE-2025-6738 - huija bicycleSharingServer UserServiceImpl.java userDao.selectUserByUserNameLike sql injection

A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this issue is the function userDao.selectUserByUserNameLike of the file UserServiceImpl.java. The manipulation of the argument Username leads t…

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-44557 -

A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.2

CVSS3.1

CVE-2025-52991 -

The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manip…

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-50367 -

A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 6:14 p.m.

7.3

CVSS3.1

CVE-2025-50528 -

A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 6:14 p.m.

6.3

CVSS3.1

CVE-2025-44163 -

RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command …

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 8:38 p.m.

6.5

CVSS3.1

CVE-2025-50369 -

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifyi…

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 6:13 p.m.

2.2

CVSS3.1

CVE-2025-47823 -

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 5:24 p.m.

6.4

CVSS3.1

CVE-2025-47822 -

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 5:25 p.m.

2.2

CVSS3.1

CVE-2025-47821 -

Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.

πŸ“… Published: June 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 5:24 p.m.
Total resulsts: 349182
Page 4871 of 34,919
Β« previous page Β» next page
Filters