5.3

CVSS4.0

CVE-2025-3561 - ghostxbh uzy-ssm-mall cross-site request forgery

A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The ven…

πŸ“… Published: April 14, 2025, 10 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:08 p.m.

5.1

CVSS4.0

CVE-2025-3560 - ghostxbh uzy-ssm-mall product cross site scripting

A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed …

πŸ“… Published: April 14, 2025, 9:31 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:08 p.m.

5.3

CVSS4.0

CVE-2025-3559 - ghostxbh uzy-ssm-mall 20 ForeProductListController sql injection

A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The expl…

πŸ“… Published: April 14, 2025, 9 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:11 p.m.

5.3

CVSS4.0

CVE-2025-3558 - ghostxbh uzy-ssm-mall uploadUserHeadImage unrestricted upload

A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has b…

πŸ“… Published: April 14, 2025, 8:31 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:15 p.m.

2.1

CVSS4.0

CVE-2025-24859 - Apache Roller: Insufficient Session Expiration on Password Change

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing sessions remain active and usable. This a…

πŸ“… Published: April 14, 2025, 8:18 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.3

CVSS4.0

CVE-2025-3557 - ScriptAndTools eCommerce-website-in-PHP cross-site request forgery

A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the…

πŸ“… Published: April 14, 2025, 8 a.m. πŸ”„ Last Modified: July 17, 2025, 7:12 p.m.

7.3

CVSS3.1

CVE-2025-31344 - The giflib open-source component has a buffer overflow vulnerability

Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.

πŸ“… Published: April 14, 2025, 7:49 a.m. πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.

6.3

CVSS4.0

CVE-2025-3556 - ScriptAndTools eCommerce-website-in-PHP login.php excessive authentication

A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launche…

πŸ“… Published: April 14, 2025, 7:31 a.m. πŸ”„ Last Modified: July 17, 2025, 7:18 p.m.

6.3

CVSS4.0

CVE-2025-3555 - ScriptAndTools eCommerce-website-in-PHP login.php excessive authentication

A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The com…

πŸ“… Published: April 14, 2025, 7 a.m. πŸ”„ Last Modified: July 17, 2025, 7:22 p.m.

4.7

CVSS3.1

CVE-2025-32093 - Syatem admin profile modification by delegated granular administration role

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system admi…

πŸ“… Published: April 14, 2025, 6:57 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 3:02 p.m.
Total resulsts: 343924
Page 5369 of 34,393
Β« previous page Β» next page
Filters