6.8

CVSS3.1

CVE-2025-5382 -

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

πŸ“… Published: June 5, 2025, 1:37 p.m. πŸ”„ Last Modified: July 2, 2025, 2:36 p.m.

5

CVSS3.1

CVE-2025-3768 -

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

πŸ“… Published: June 5, 2025, 1:36 p.m. πŸ”„ Last Modified: July 2, 2025, 1:06 p.m.

4.8

CVSS4.0

CVE-2025-5661 - code-projects Traffic Offense Reporting System Setting save-settings.php cross site scripting

A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part of the file /save-settings.php of the component Setting Handler. The manipulation of the argument site_name leads to cross site scripting. It is possib…

πŸ“… Published: June 5, 2025, 1:31 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 3:52 p.m.

6.5

CVSS3.1

CVE-2025-27754 - Extension - rsjoomla.com - A stored XSS vulnerability RSBlog! component 1.11.6 - 1.14.4 for Joomla

A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected …

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: June 16, 2025, 5:28 p.m.

6.5

CVSS3.1

CVE-2025-27753 - Extension - rsjoomla.com - A SQLi vulnerability RSMediaGallery component 1.7.4 - 2.1.6 for Joomla

A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized i…

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-27445 - Extension - rsjoomla.com - A path traversal vulnerability RSFirewall component 2.9.7 - 3.1.5 for Jo…

A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, al…

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-30084 - Extension - rsjoomla.com - Reflected XSS vulnerability RSMail! component 1.19.20-1.22.26 for Joomla

A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or o…

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 3:14 p.m.

5.3

CVSS4.0

CVE-2025-5660 - PHPGurukul Complaint Management System register-complaint.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functionality of the file /user/register-complaint.php. The manipulation of the argument noc leads to sql injection. The attack may be launched rem…

πŸ“… Published: June 5, 2025, 1 p.m. πŸ”„ Last Modified: June 6, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-5659 - PHPGurukul Complaint Management System profile.php sql injection

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit…

πŸ“… Published: June 5, 2025, 1 p.m. πŸ”„ Last Modified: June 6, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-5658 - PHPGurukul Complaint Management System updatecomplaint.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatecomplaint.php. The manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: June 5, 2025, 12:31 p.m. πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.
Total resulsts: 349182
Page 5165 of 34,919
Β« previous page Β» next page
Filters