8

CVSS3.1

CVE-2025-51672 -

A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-companies.php file and allows remote attackers to execute arbitrary SQL code via the companyname parameter in a POST request.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: July 13, 2025, 9:48 p.m.

6.5

CVSS3.1

CVE-2025-52555 - CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by root to gain access. The result of this is that โ€ฆ

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-4437 - Cri-o: large /etc/passwd file may lead to denial of service

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a highโ€ฆ

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-51671 -

A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: July 13, 2025, 9:48 p.m.

6.1

CVSS3.1

CVE-2025-44141 -

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: March 4, 2026, 6:45 p.m.

9.8

CVSS3.1

CVE-2025-29331 -

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: July 10, 2025, 2:49 p.m.

9.1

CVSS3.1

CVE-2025-49603 -

Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-30131 -

An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based webshell. Once a file is uploaded, the attacker can execute commands with root privileges, gaining full control over the dashcam. Addโ€ฆ

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2025, 8:24 p.m.

9.6

CVSS3.1

CVE-2024-52928 -

Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: July 10, 2025, 12:59 a.m.

5.4

CVSS3.1

CVE-2025-50350 -

PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.

๐Ÿ“… Published: June 26, 2025, midnight ๐Ÿ”„ Last Modified: July 13, 2025, 9:48 p.m.
Total resulsts: 349182
Page 4885 of 34,919
ยซ previous page ยป next page
Filters