4.4

CVSS3.1

CVE-2025-3435 - MangBoard WP <= 1.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Board Header…

The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin…

πŸ“… Published: April 24, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

8.6

CVSS4.0

CVE-2025-1976 - Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

πŸ“… Published: April 24, 2025, 2:55 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.5

CVSS3.1

CVE-2025-44135 -

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 1:04 p.m.

4.8

CVSS3.1

CVE-2025-29568 -

A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS).

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 1:09 p.m.

8

CVSS3.1

CVE-2025-25777 -

Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 1:41 p.m.

5.9

CVSS3.1

CVE-2025-46419 -

Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:31 p.m.

6.8

CVSS3.1

CVE-2025-46421 - Libsoup: information disclosure may leads libsoup client sends authorization header to a different …

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:35 a.m.

6.5

CVSS3.1

CVE-2025-46420 - Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:06 a.m.

6.8

CVSS4.0

CVE-2025-46417 -

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:39 p.m.

6.5

CVSS3.1

CVE-2025-44134 -

A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 1:05 p.m.
Total resulsts: 343984
Page 5164 of 34,399
Β« previous page Β» next page
Filters