6.9

CVSS4.0

CVE-2025-5079 - PHPGurukul/Campcodes Online Shopping Portal updateorder.php sql injection

A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation of the argument remark can lead to sql injection. The attack may be performed from remote. The exploit has …

πŸ“… Published: May 22, 2025, 2:31 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:24 p.m.

4.3

CVSS4.0

CVE-2025-32915 - Sensitive data exposed during automatic agent updates

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.

πŸ“… Published: May 22, 2025, 2:16 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 3:36 p.m.

2.7

CVSS3.1

CVE-2025-1110 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

πŸ“… Published: May 22, 2025, 2:02 p.m. πŸ”„ Last Modified: May 29, 2025, 3:58 p.m.

6.9

CVSS4.0

CVE-2025-5078 - PHPGurukul/Campcodes Online Shopping Portal subcategory.php sql injection

A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category results in sql injection. The attack is possible to be carried out remotely. The exploit is now publi…

πŸ“… Published: May 22, 2025, 2 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:24 p.m.

6.9

CVSS4.0

CVE-2025-5077 - Campcodes Online Shopping Portal edit-subcategory.php sql injection

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit …

πŸ“… Published: May 22, 2025, 2 p.m. πŸ”„ Last Modified: May 28, 2025, 1:53 a.m.

6.5

CVSS3.1

CVE-2025-4575 - The x509 application adds trusted use instead of rejected use

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use. A copy & paste…

πŸ“… Published: May 22, 2025, 1:36 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-5076 - FreeFloat FTP Server SEND Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public …

πŸ“… Published: May 22, 2025, 1:31 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

6.5

CVSS3.1

CVE-2025-2853 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

πŸ“… Published: May 22, 2025, 1:30 p.m. πŸ”„ Last Modified: May 29, 2025, 3:58 p.m.

6.5

CVSS3.1

CVE-2025-3111 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

πŸ“… Published: May 22, 2025, 1:30 p.m. πŸ”„ Last Modified: May 29, 2025, 3:58 p.m.

4.9

CVSS3.1

CVE-2025-4979 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP res…

πŸ“… Published: May 22, 2025, 1:30 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:33 p.m.
Total resulsts: 345780
Page 4948 of 34,578
Β« previous page Β» next page
Filters