6.9

CVSS4.0

CVE-2025-6339 - ponaravindb Hospital Management System func3.php sql injection

A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /func3.php. The manipulation of the argument username1 leads to sql injection. The attack may be launched remotely. The exploit ha…

📅 Published: June 20, 2025, noon 🔄 Last Modified: Oct. 31, 2025, 8:12 p.m.

8.7

CVSS4.0

CVE-2025-6337 - TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argum…

📅 Published: June 20, 2025, noon 🔄 Last Modified: Aug. 1, 2025, 10:18 p.m.

8.7

CVSS4.0

CVE-2025-6336 - TOTOLINK EX1200T HTTP POST Request formTmultiAP buffer overflow

A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible…

📅 Published: June 20, 2025, 11:31 a.m. 🔄 Last Modified: June 26, 2025, 6:28 p.m.

7.2

CVSS3.1

CVE-2025-4102 - Beaver Builder Plugin (Starter Version) <= 2.9.1 - Authenticated (Administrator+) Arbitrary File Up…

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level…

📅 Published: June 20, 2025, 11:16 a.m. 🔄 Last Modified: April 22, 2026, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-6335 - DedeCMS Template dedetag.class.php command injection

A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads to command injection. The attack may be initiated remotely. …

📅 Published: June 20, 2025, 11 a.m. 🔄 Last Modified: July 18, 2025, 12:25 p.m.

8.7

CVSS4.0

CVE-2025-6334 - D-Link DIR-867 Query String strncpy stack-based overflow

A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of the component Query String Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the …

📅 Published: June 20, 2025, 11 a.m. 🔄 Last Modified: July 11, 2025, 3:55 p.m.

5.3

CVSS4.0

CVE-2025-6333 - PHPGurukul Directory Management System admin-profile.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to initiate the attack remotely. The explo…

📅 Published: June 20, 2025, 10:31 a.m. 🔄 Last Modified: June 26, 2025, 6:35 p.m.

5.3

CVSS4.0

CVE-2025-6332 - PHPGurukul Directory Management System manage-directory.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sql injection. The attack may be launched remo…

📅 Published: June 20, 2025, 10:31 a.m. 🔄 Last Modified: June 26, 2025, 6:39 p.m.

9.9

CVSS3.1

CVE-2025-4981 - Path Traversal Leading to RCE by Any Authenticated Mattermost User

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal seque…

📅 Published: June 20, 2025, 10:27 a.m. 🔄 Last Modified: July 8, 2025, 5:59 p.m.

4.8

CVSS4.0

CVE-2025-5963 - TCC Bypass via Dylib Injection in Postbox

The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-environment-variables" and "com.apple.security.cs.disable-library-validation" allows for Dynamic Library (Dylib) injection. A local attacker with unprivileged access can use environmen…

📅 Published: June 20, 2025, 10:01 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4944 of 34,919
« previous page » next page
Filters