3.1

CVSS3.1

CVE-2023-5600 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk …

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:52 p.m.

6.9

CVSS4.0

CVE-2025-6362 - code-projects Simple Pizza Ordering System editpro.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /editpro.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely.

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:30 p.m.

6.9

CVSS4.0

CVE-2025-6361 - code-projects Simple Pizza Ordering System adds.php sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /adds.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely.

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:33 p.m.

6.9

CVSS4.0

CVE-2025-6360 - code-projects Simple Pizza Ordering System portal.php sql injection

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /portal.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed t…

πŸ“… Published: June 20, 2025, 7 p.m. πŸ”„ Last Modified: June 26, 2025, 3:35 p.m.

10

CVSS4.0

CVE-2025-34030 - sar2html OS Command Injection

An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the…

πŸ“… Published: June 20, 2025, 6:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-34029 - Edimax EW-7438RPn Mini OS Command Injection via syscmd.asp

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell com…

πŸ“… Published: June 20, 2025, 6:38 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

9.4

CVSS4.0

CVE-2025-34024 - Edimax EW-7438RPn Mini OS Command Injection via mp.asp

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters …

πŸ“… Published: June 20, 2025, 6:38 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

8.5

CVSS4.0

CVE-2025-34023 - Karel IP Phone IP1211 Path Traversal

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted pat…

πŸ“… Published: June 20, 2025, 6:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-34022 - Selea Targa IP OCR-ANPR Camera Path Traversal

A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the β€œDownload Archive in Storage” page fails…

πŸ“… Published: June 20, 2025, 6:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS4.0

CVE-2025-34021 - Selea Targa IP OCR-ANPR Camera Server-Side Request Forgery

A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The application fails to validate user-supplied input in JSON P…

πŸ“… Published: June 20, 2025, 6:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4930 of 34,919
Β« previous page Β» next page
Filters