7.6

CVSS3.1

CVE-2025-0966 - IBM InfoSphere Information Server SQL injection

IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

๐Ÿ“… Published: June 25, 2025, 2:40 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-36004 - IBM i privilege escalation

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

๐Ÿ“… Published: June 25, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.4

CVSS3.1

CVE-2025-5585 - SiteOrigin Widgets Bundle <= 1.68.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via โ€ฆ

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with โ€ฆ

๐Ÿ“… Published: June 25, 2025, 2:22 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10:30 p.m.

5.3

CVSS4.0

CVE-2025-6583 - SourceCodester Best Salon Management System view-appointment.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view-appointment.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: July 2, 2025, 4:46 p.m.

7.1

CVSS3.1

CVE-2025-25905 -

Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: July 13, 2025, 9:48 p.m.

7.5

CVSS3.1

CVE-2025-45333 -

berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 7:06 p.m.

7.5

CVSS3.1

CVE-2025-45332 -

vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 7:07 p.m.

7.1

CVSS3.1

CVE-2024-27685 -

SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: July 2, 2025, 4:16 p.m.

7.1

CVSS3.1

CVE-2023-44915 -

A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2025-44206 -

Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4897 of 34,919
ยซ previous page ยป next page
Filters