6.5

CVSS3.1

CVE-2025-46176 -

Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 3:47 p.m.

9.8

CVSS3.1

CVE-2024-51101 -

PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: May 29, 2025, 4:15 p.m.

6.4

CVSS3.1

CVE-2025-48695 -

An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to escalate their privilege by abusing the following API due to the lack of access control: /api/v2/users/user/<user id>/role/ROLE/<Target role> (admin access can be achieved).

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-51102 -

PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 3:47 p.m.

4.3

CVSS3.1

CVE-2025-48735 -

A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230220 allows remote attackers to obtain sensitive information from the database via crafted input in the request body.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-48738 -

An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exhโ€ฆ

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2023-53154 - cjson: Heap based buffer overflow at cJSON_ParseWithLength function

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

4

CVSS3.1

CVE-2025-48708 - Ghostscript: Ghostscript Argument Sanitization Vulnerability

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.4

CVSS3.1

CVE-2025-48701 -

openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

๐Ÿ“… Published: May 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-4692 - ABUP IoT Cloud Platform Incorrect Privilege Assignment

Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed byโ€ฆ

๐Ÿ“… Published: May 22, 2025, 11:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347766
Page 5139 of 34,777
ยซ previous page ยป next page
Filters