9.8

CVSS3.1

CVE-2025-5099 - KL-001-2025-004: Mobile Dynamix PrinterShare Mobile Print Out-of-bounds Write

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

πŸ“… Published: May 23, 2025, 1:05 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:30 p.m.

4.7

CVSS4.0

CVE-2025-2394 - Disclosure of Alibaba (OSS) Keys In Ecovacs Home Android and iOS Mobile Applications

Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.

πŸ“… Published: May 23, 2025, 12:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-51108 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate par…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-51099 -

A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchda…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:47 p.m.

4.6

CVSS4.0

CVE-2025-48739 -

A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows remote authenticated attackers with admin permissions (allowing them to access specific API endpoints) to manipulate URLs to direct r…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-48704 -

Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 9, 2025, 7 p.m.

0.0

CVE-2025-48699 -

DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 8:15 p.m.

5.9

CVSS4.0

CVE-2025-48740 -

A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic auth…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-51107 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and emai…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2024-51103 -

PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/password-recovery.php via the emailid and id parameters.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:47 p.m.
Total resulsts: 347742
Page 5135 of 34,775
Β« previous page Β» next page
Filters