2.6

CVSS3.1

CVE-2025-47794 - Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permiss…

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud runni…

📅 Published: May 16, 2025, 2:35 p.m. 🔄 Last Modified: Sept. 30, 2025, 7:37 p.m.

4.3

CVSS3.1

CVE-2025-47793 - Nextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attach…

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfo…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: Sept. 8, 2025, 9:54 p.m.

5.3

CVSS4.0

CVE-2025-4782 - SourceCodester/oretnom23 Stock Management System view_receiving sql injection

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initia…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: May 23, 2025, 1:04 p.m.

5.3

CVSS4.0

CVE-2025-4781 - PHPGurukul Park Ticketing Management System forgot-password.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an unknown function of the file /forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. It is possible to launch the attack remotely. The expl…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: May 21, 2025, 8:59 p.m.

5

CVSS3.1

CVE-2025-47792 - Nextcloud Desktop 3rdparty applications can create share links via socket API

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextc…

📅 Published: May 16, 2025, 2:13 p.m. 🔄 Last Modified: Sept. 8, 2025, 9:22 p.m.

4.3

CVSS3.1

CVE-2025-47791 - Nextcloud Server's test remote endpoint is not rate limited

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests t…

📅 Published: May 16, 2025, 2:09 p.m. 🔄 Last Modified: Sept. 19, 2025, 5:41 p.m.

6.4

CVSS3.1

CVE-2025-47790 - Nextcloud Server doesn't request second factor after session timeout

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirma…

📅 Published: May 16, 2025, 2:02 p.m. 🔄 Last Modified: Sept. 30, 2025, 7:59 p.m.

5.3

CVSS4.0

CVE-2025-4780 - PHPGurukul Park Ticketing Management System foreigner-search.php sql injection

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The ex…

📅 Published: May 16, 2025, 2 p.m. 🔄 Last Modified: June 5, 2025, 7:36 p.m.

4.3

CVSS3.1

CVE-2025-32962 - Flask-AppBuilder open redirect vulnerability using HTTP host injection

Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` con…

📅 Published: May 16, 2025, 1:51 p.m. 🔄 Last Modified: Sept. 19, 2025, 6:04 p.m.

8.7

CVSS4.0

CVE-2025-4600 - HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked En…

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a …

📅 Published: May 16, 2025, 1:47 p.m. 🔄 Last Modified: Sept. 26, 2025, 5:18 p.m.
Total resulsts: 349182
Page 5370 of 34,919
« previous page » next page
Filters