6.9

CVSS4.0

CVE-2025-4816 - SourceCodester Doctor's Appointment System GET Parameter appointment.php sql injection

A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to init…

πŸ“… Published: May 17, 2025, 3 a.m. πŸ”„ Last Modified: May 28, 2025, 12:59 a.m.

6.9

CVSS4.0

CVE-2025-4815 - Campcodes Sales and Inventory System supplier_update.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/supplier_update.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The explo…

πŸ“… Published: May 17, 2025, 2:31 a.m. πŸ”„ Last Modified: May 28, 2025, 5:08 p.m.

6.9

CVSS4.0

CVE-2025-4814 - Campcodes Sales and Inventory System supplier_add.php sql injection

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_add.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. T…

πŸ“… Published: May 17, 2025, 2 a.m. πŸ”„ Last Modified: May 28, 2025, 1:17 p.m.

6.5

CVSS3.1

CVE-2024-47893 - GPU DDK - OOB read and write of the shared KMD/FW memory heap (VZ/TEE setups)

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.

πŸ“… Published: May 17, 2025, 12:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-1706 - GPU DDK - Improper locking when accessing the pvr_exp_fence object

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

πŸ“… Published: May 17, 2025, 12:40 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-48187 -

RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.

πŸ“… Published: May 17, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:29 p.m.

6.9

CVSS4.0

CVE-2025-4813 - PHPGurukul Human Metapneumovirus Testing Management System edit-phlebotomist.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to launch the atta…

πŸ“… Published: May 16, 2025, 9:31 p.m. πŸ”„ Last Modified: June 4, 2025, 4:10 p.m.

6.9

CVSS4.0

CVE-2025-4812 - PHPGurukul Human Metapneumovirus Testing Management System profile.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated…

πŸ“… Published: May 16, 2025, 9:31 p.m. πŸ”„ Last Modified: June 4, 2025, 4:08 p.m.

6.9

CVSS4.0

CVE-2025-4811 - CodeAstro Pharmacy Management System Login index.php sql injection

A vulnerability was found in CodeAstro Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack may be launched remo…

πŸ“… Published: May 16, 2025, 9 p.m. πŸ”„ Last Modified: June 4, 2025, 4:08 p.m.

6.5

CVSS3.1

CVE-2022-4363 - Wholesale Market <= 2.2.2 - Settings Update via CSRF

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack

πŸ“… Published: May 16, 2025, 8:33 p.m. πŸ”„ Last Modified: June 12, 2025, 4:46 p.m.
Total resulsts: 349182
Page 5360 of 34,919
Β« previous page Β» next page
Filters