9.8

CVSS3.1

CVE-2025-4389 - Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File Upload

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated attackers…

πŸ“… Published: May 17, 2025, 5:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4818 - SourceCodester Doctor's Appointment System GET Parameter delete-doctor.php sql injection

A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/delete-doctor.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack …

πŸ“… Published: May 17, 2025, 5 a.m. πŸ”„ Last Modified: May 28, 2025, 12:58 a.m.

6.9

CVSS4.0

CVE-2025-4817 - Sourcecodester Doctor's Appointment System GET Parameter delete-appointment.php sql injection

A vulnerability was found in Sourcecodester Doctor's Appointment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete-appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The at…

πŸ“… Published: May 17, 2025, 4 a.m. πŸ”„ Last Modified: May 28, 2025, 12:59 a.m.

6.1

CVSS3.1

CVE-2025-4194 - AlT Monitoring <= 1.0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject…

πŸ“… Published: May 17, 2025, 3:24 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

6.1

CVSS3.1

CVE-2025-4189 - Audio Comments Plugin <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the 'audio-comments/audior-settings.php' page. This makes it possible for unauthenticated attackers to upda…

πŸ“… Published: May 17, 2025, 3:24 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

6.9

CVSS4.0

CVE-2025-4816 - SourceCodester Doctor's Appointment System GET Parameter appointment.php sql injection

A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to init…

πŸ“… Published: May 17, 2025, 3 a.m. πŸ”„ Last Modified: May 28, 2025, 12:59 a.m.

6.9

CVSS4.0

CVE-2025-4815 - Campcodes Sales and Inventory System supplier_update.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/supplier_update.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The explo…

πŸ“… Published: May 17, 2025, 2:31 a.m. πŸ”„ Last Modified: May 28, 2025, 5:08 p.m.

6.9

CVSS4.0

CVE-2025-4814 - Campcodes Sales and Inventory System supplier_add.php sql injection

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_add.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. T…

πŸ“… Published: May 17, 2025, 2 a.m. πŸ”„ Last Modified: May 28, 2025, 1:17 p.m.

6.5

CVSS3.1

CVE-2024-47893 - GPU DDK - OOB read and write of the shared KMD/FW memory heap (VZ/TEE setups)

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.

πŸ“… Published: May 17, 2025, 12:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-1706 - GPU DDK - Improper locking when accessing the pvr_exp_fence object

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

πŸ“… Published: May 17, 2025, 12:40 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346667
Page 5108 of 34,667
Β« previous page Β» next page
Filters