9.3

CVSS4.0

CVE-2025-25038 - MiniDVBLinux Root Command Injection

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execut…

πŸ“… Published: June 20, 2025, 6:36 p.m. πŸ”„ Last Modified: April 7, 2026, 2:08 p.m.

9.3

CVSS4.0

CVE-2025-25037 - Aquatronica Controller System Complete Information Disclosure

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration …

πŸ“… Published: June 20, 2025, 6:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-25034 - SugarCRM PHP Deserialization RCE

A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before passing it to the uns…

πŸ“… Published: June 20, 2025, 6:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-6359 - code-projects Simple Pizza Ordering System cashconfirm.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cashconfirm.php. The manipulation of the argument transactioncode leads to sql injection. The attack may be launched remotely…

πŸ“… Published: June 20, 2025, 6:31 p.m. πŸ”„ Last Modified: June 26, 2025, 12:59 p.m.

8.1

CVSS3.1

CVE-2024-4994 - Cross-Site Request Forgery (CSRF) in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutati…

πŸ“… Published: June 20, 2025, 6:14 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:52 p.m.

6.5

CVSS3.1

CVE-2024-4025 - Inefficient Regular Expression Complexity in GitLab

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

πŸ“… Published: June 20, 2025, 6:14 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-6358 - code-projects Simple Pizza Ordering System saveorder.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saveorder.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The …

πŸ“… Published: June 20, 2025, 6 p.m. πŸ”„ Last Modified: June 26, 2025, 1:04 p.m.

6.9

CVSS4.0

CVE-2025-6357 - code-projects Simple Pizza Ordering System paymentportal.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:10 p.m.

6.9

CVSS4.0

CVE-2025-6356 - code-projects Simple Pizza Ordering System addmem.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /addmem.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:17 p.m.

2.7

CVSS4.0

CVE-2025-52484 - RISC Zero zkVM Underconstrained Vulnerability

RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a malicious prover. The …

πŸ“… Published: June 20, 2025, 5:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4931 of 34,919
Β« previous page Β» next page
Filters