6.9

CVSS4.0

CVE-2025-4214 - PHPGuruku Online DJ Booking Management System booking-bwdates-reports-details.php sql injection

A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiatedโ€ฆ

๐Ÿ“… Published: May 2, 2025, 7:31 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 9:09 p.m.

6.9

CVSS4.0

CVE-2025-4213 - PHPGurukul Online Birth Certificate System search.php sql injection

A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit hโ€ฆ

๐Ÿ“… Published: May 2, 2025, 6 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 8:56 p.m.

6.5

CVSS3.1

CVE-2025-46332 - Information Disclosure via Flags override link

Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and prior as certain circumstances allows a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags dโ€ฆ

๐Ÿ“… Published: May 2, 2025, 5:06 p.m. ๐Ÿ”„ Last Modified: May 5, 2025, 8:54 p.m.

6.6

CVSS3.1

CVE-2025-3879 - Vaultโ€™s Azure Authentication Method bound_location Restriction Could be Bypassed on Login

Vault Community, Vault Enterprise (โ€œVaultโ€) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

๐Ÿ“… Published: May 2, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 1:39 a.m.

6.9

CVSS4.0

CVE-2025-4210 - Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgradingโ€ฆ

๐Ÿ“… Published: May 2, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: May 5, 2025, 8:54 p.m.

7.8

CVSS3.1

CVE-2025-1884 - Use-After-Free vulnerability exists in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.

๐Ÿ“… Published: May 2, 2025, 3:03 p.m. ๐Ÿ”„ Last Modified: May 5, 2025, 8:54 p.m.

7.8

CVSS3.1

CVE-2025-1883 - Out-Of-Bounds Write vulnerability exists in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted OBJร‚ย file.

๐Ÿ“… Published: May 2, 2025, 3:03 p.m. ๐Ÿ”„ Last Modified: May 5, 2025, 8:54 p.m.

4.5

CVSS3.1

CVE-2025-4166 - Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, isโ€ฆ

๐Ÿ“… Published: May 2, 2025, 2:57 p.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 12:49 a.m.

9.8

CVSS3.1

CVE-2025-3927 - CVE-2025-3927

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.

๐Ÿ“… Published: May 2, 2025, 2:36 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 2:18 p.m.

9.9

CVSS3.1

CVE-2025-2605 - Authenticated command injection

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most โ€ฆ

๐Ÿ“… Published: May 2, 2025, 12:39 p.m. ๐Ÿ”„ Last Modified: May 17, 2025, 6:15 a.m.
Total resulsts: 343825
Page 5029 of 34,383
ยซ previous page ยป next page
Filters