5.3

CVSS3.1

CVE-2025-1752 - Denial of Service in run-llama/llama_index

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the maxโ€ฆ

๐Ÿ“… Published: May 10, 2025, 1:21 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:16 p.m.

4.8

CVSS4.0

CVE-2025-4501 - code-projects Album Management System Search Albums searchalbum stack-based overflow

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has bโ€ฆ

๐Ÿ“… Published: May 10, 2025, 1 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

4.8

CVSS4.0

CVE-2025-4500 - code-projects Hotel Management System Edit Room edit stack-based overflow

A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of the component Edit Room. The manipulation of the argument roomnumber leads to stack-based buffer overflow. An attack has to be approached loโ€ฆ

๐Ÿ“… Published: May 10, 2025, 12:31 p.m. ๐Ÿ”„ Last Modified: May 16, 2025, 2:16 p.m.

4.8

CVSS4.0

CVE-2025-4499 - code-projects Simple Hospital Management System Add Information add stack-based overflow

A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].disease leads to stack-based buffer overflow. The attack needโ€ฆ

๐Ÿ“… Published: May 10, 2025, 11:31 a.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.4

CVSS3.1

CVE-2025-3878 - SMS Alert Order Notifications โ€“ WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Siโ€ฆ

The SMS Alert Order Notifications โ€“ WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poโ€ฆ

๐Ÿ“… Published: May 10, 2025, 11:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:13 p.m.

8.8

CVSS3.1

CVE-2025-3876 - SMS Alert Order Notifications โ€“ WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalaโ€ฆ

The SMS Alert Order Notifications โ€“ WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Suโ€ฆ

๐Ÿ“… Published: May 10, 2025, 11:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:40 p.m.

4.8

CVSS4.0

CVE-2025-4498 - code-projects Simple Bus Reservation System Install Bus install stack-based overflow

A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is possible to launch the attack on the local hosโ€ฆ

๐Ÿ“… Published: May 10, 2025, 10 a.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-2158 - WordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticatโ€ฆ

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.5 via the Post custom fields. This makes it possible for authenticated attackers, with Contributor-level access and aโ€ฆ

๐Ÿ“… Published: May 10, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:12 p.m.

4.8

CVSS4.0

CVE-2025-4497 - code-projects Simple Banking System Sign In buffer overflow

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has beโ€ฆ

๐Ÿ“… Published: May 10, 2025, 7 a.m. ๐Ÿ”„ Last Modified: May 16, 2025, 2:51 p.m.

6.4

CVSS3.1

CVE-2025-2944 - Jeg Elementor Kit <= 2.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Buโ€ฆ

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up to, and including, 2.6.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible forโ€ฆ

๐Ÿ“… Published: May 10, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:02 p.m.
Total resulsts: 344154
Page 4967 of 34,416
ยซ previous page ยป next page
Filters