5.3

CVSS4.0

CVE-2024-38866 - Livestatus Injection in dynmaps

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection

πŸ“… Published: May 27, 2025, 7:01 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.1

CVSS4.0

CVE-2025-5232 - PHPGurukul Student Study Center Management System report.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1.0. This issue affects some unknown processing of the file /admin/report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated …

πŸ“… Published: May 27, 2025, 5 a.m. πŸ”„ Last Modified: June 10, 2025, 3:12 p.m.

1.2

CVSS4.0

CVE-2025-48382 - Fess has Insecure Temporary File Permissions

Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without explicitly setting restrictive permissions. This could lead to potential information disclosure, allowing unauthorized local …

πŸ“… Published: May 27, 2025, 4:32 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:33 p.m.

6.9

CVSS4.0

CVE-2025-5231 - PHPGurukul Company Visitor Management System forgot-password.php sql injection

A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been d…

πŸ“… Published: May 27, 2025, 4:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:11 p.m.

6.8

CVSS4.0

CVE-2025-48054 - Radashi Vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype…

Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript…

πŸ“… Published: May 27, 2025, 4:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5230 - PHPGurukul Online Nurse Hiring System bwdates-report-details.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. Th…

πŸ“… Published: May 27, 2025, 4 a.m. πŸ”„ Last Modified: June 10, 2025, 3:11 p.m.

6.9

CVSS4.0

CVE-2025-5229 - Campcodes Online Hospital Management System view-patient.php sql injection

A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/view-patient.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely.…

πŸ“… Published: May 27, 2025, 3:31 a.m. πŸ”„ Last Modified: May 28, 2025, 8:38 p.m.

8.7

CVSS4.0

CVE-2025-5228 - D-Link DI-8100 jhttpd login.cgi httpd_get_parm stack-based overflow

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated with…

πŸ“… Published: May 27, 2025, 3 a.m. πŸ”„ Last Modified: July 15, 2025, 5:24 p.m.

6.9

CVSS4.0

CVE-2025-5227 - PHPGurukul Small CRM manage-tickets.php sql injection

A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown processing of the file /admin/manage-tickets.php. The manipulation of the argument aremark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed t…

πŸ“… Published: May 27, 2025, 3 a.m. πŸ”„ Last Modified: June 10, 2025, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-5226 - PHPGurukul Small CRM change-password.php sql injection

A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-password.php. The manipulation of the argument oldpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclose…

πŸ“… Published: May 27, 2025, 2:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:43 p.m.
Total resulsts: 349182
Page 5247 of 34,919
Β« previous page Β» next page
Filters