8.8

CVSS3.1

CVE-2024-48013 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

๐Ÿ“… Published: March 17, 2025, 4:45 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-2385 - code-projects Modern Bag login.php sql injection

A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument userEmail/userPassword leads to sql injection. The attack can be initiated remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: March 17, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 6:15 p.m.

8.2

CVSS3.1

CVE-2025-2241 - Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sโ€ฆ

๐Ÿ“… Published: March 17, 2025, 4:27 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-2384 - code-projects Real Estate Property Management System Parameter InsertCustomer.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txtName/txtAddress/cmbCity/txtEmail/cmbGender/tโ€ฆ

๐Ÿ“… Published: March 17, 2025, 4 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-2383 - PHPGurukul Doctor Appointment Management System search.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launchโ€ฆ

๐Ÿ“… Published: March 17, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 7:15 p.m.

6.3

CVSS4.0

CVE-2025-1774 - Logs manipulation in BotSense

Incorrect string encodingย vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue โ€ฆ

๐Ÿ“… Published: March 17, 2025, 3:05 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:17 p.m.

6.9

CVSS4.0

CVE-2025-2382 - PHPGurukul Online Banquet Booking System booking-search.php sql injection

A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotelyโ€ฆ

๐Ÿ“… Published: March 17, 2025, 3 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:49 p.m.

2.1

CVSS4.0

CVE-2025-27512 - Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods

Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot the system into the dโ€ฆ

๐Ÿ“… Published: March 17, 2025, 2:46 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:15 p.m.

6.9

CVSS4.0

CVE-2025-2381 - PHPGurukul Curfew e-Pass Management System search-pass.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit โ€ฆ

๐Ÿ“… Published: March 17, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:15 p.m.

10

CVSS4.0

CVE-2025-1398 - macOS TCC Bypass via Code Injection

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

๐Ÿ“… Published: March 17, 2025, 2:19 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:15 p.m.
Total resulsts: 285589
Page 5 of 28,559
ยซ previous page ยป next page
Filters