6.2

CVSS3.1

CVE-2025-49009 - Para Inserts Sensitive Information into Log File for Facebook authentication

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access…

πŸ“… Published: June 5, 2025, 4:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-48493 - Yii 2 Redis may expose AUTH paramters in logs in case of connection failure

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacke…

πŸ“… Published: June 5, 2025, 4:33 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 2:08 p.m.

5.3

CVSS4.0

CVE-2025-5669 - PHPGurukul Medical Card Generation System unreadenq.php sql injection

A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/unreadenq.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclos…

πŸ“… Published: June 5, 2025, 4:31 p.m. πŸ”„ Last Modified: June 6, 2025, 7:39 p.m.

5.3

CVSS4.0

CVE-2025-5668 - PHPGurukul Medical Card Generation System readenq.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been discl…

πŸ“… Published: June 5, 2025, 4:31 p.m. πŸ”„ Last Modified: June 6, 2025, 8:12 p.m.

6.9

CVSS4.0

CVE-2025-5667 - FreeFloat FTP Server REIN Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component REIN Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the pub…

πŸ“… Published: June 5, 2025, 4 p.m. πŸ”„ Last Modified: June 24, 2025, 3:22 p.m.

6.9

CVSS4.0

CVE-2025-5666 - FreeFloat FTP Server XMKD Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component XMKD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed t…

πŸ“… Published: June 5, 2025, 3:31 p.m. πŸ”„ Last Modified: June 24, 2025, 3:22 p.m.

6.9

CVSS4.0

CVE-2025-5665 - FreeFloat FTP Server XCWD Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component XCWD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…

πŸ“… Published: June 5, 2025, 3 p.m. πŸ”„ Last Modified: June 24, 2025, 3:22 p.m.

6.9

CVSS4.0

CVE-2025-5664 - FreeFloat FTP Server RESTART Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component RESTART Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and ma…

πŸ“… Published: June 5, 2025, 2:31 p.m. πŸ”„ Last Modified: June 24, 2025, 3:21 p.m.

6.9

CVSS4.0

CVE-2025-5663 - PHPGurukul Auto Taxi Stand Management System search-autoortaxi.php sql injection

A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. …

πŸ“… Published: June 5, 2025, 2 p.m. πŸ”„ Last Modified: June 6, 2025, 6:43 p.m.

5

CVSS3.1

CVE-2025-0691 -

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

πŸ“… Published: June 5, 2025, 1:41 p.m. πŸ”„ Last Modified: July 2, 2025, 1:11 p.m.
Total resulsts: 349182
Page 5164 of 34,919
Β« previous page Β» next page
Filters