5.3

CVSS4.0

CVE-2025-5657 - PHPGurukul Complaint Management System manage-users.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has …

πŸ“… Published: June 5, 2025, noon πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

8.8

CVSS3.1

CVE-2011-10007 - File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` enco…

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a…

πŸ“… Published: June 5, 2025, 11:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-5656 - PHPGurukul Complaint Management System edit-category.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-category.php. The manipulation of the argument description leads to sql injection. The attack can be initiated remotely. The exp…

πŸ“… Published: June 5, 2025, 11:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

6.4

CVSS3.1

CVE-2025-5341 - Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id an…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it po…

πŸ“… Published: June 5, 2025, 11:15 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 a.m.

8.8

CVSS3.1

CVE-2025-5701 - HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to u…

πŸ“… Published: June 5, 2025, 11:15 a.m. πŸ”„ Last Modified: April 22, 2026, 3 p.m.

5.3

CVSS4.0

CVE-2025-5655 - PHPGurukul Complaint Management System edit-subcategory.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument subcategory leads to sql injection. It is possible to initiate the attack remotely. The…

πŸ“… Published: June 5, 2025, 11 a.m. πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

5.3

CVSS4.0

CVE-2025-5654 - PHPGurukul Complaint Management System edit-state.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-state.php. The manipulation of the argument description leads to sql injection. The attack may be launched remotely. The e…

πŸ“… Published: June 5, 2025, 11 a.m. πŸ”„ Last Modified: June 10, 2025, 3:04 p.m.

5.3

CVSS4.0

CVE-2025-5653 - PHPGurukul Complaint Management System between-date-userreport.php sql injection

A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/between-date-userreport.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can…

πŸ“… Published: June 5, 2025, 10:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:05 p.m.

9.3

CVSS4.0

CVE-2025-4568 - SQL Injection in 2ClickPortal

Improper neutralization of input provided by an unauthorized user into changes__reference_id parameter in URL allows for boolean-based Blind SQL Injection attacks.

πŸ“… Published: June 5, 2025, 10:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-5652 - PHPGurukul Complaint Management System between-date-complaintreport.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/between-date-complaintreport.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the atta…

πŸ“… Published: June 5, 2025, 10 a.m. πŸ”„ Last Modified: June 6, 2025, 6:31 p.m.
Total resulsts: 349182
Page 5166 of 34,919
Β« previous page Β» next page
Filters