9.8

CVSS3.1

CVE-2025-28056 -

rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 6:07 p.m.

5.4

CVSS3.1

CVE-2025-45859 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 6:25 p.m.

9.8

CVSS3.1

CVE-2025-44831 -

EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 6:26 p.m.

9.8

CVSS3.1

CVE-2025-45858 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: May 23, 2025, 6:57 p.m.

7.2

CVSS3.1

CVE-2025-28057 -

owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 2:09 a.m.

6.5

CVSS3.1

CVE-2025-45746 -

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and becaโ€ฆ

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-45861 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: May 15, 2025, 6:37 p.m.

7.5

CVSS3.1

CVE-2025-28055 -

upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 1:58 a.m.

6.1

CVSS3.1

CVE-2025-47204 -

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability expโ€ฆ

๐Ÿ“… Published: May 13, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 2:02 a.m.

9.8

CVSS3.1

CVE-2023-49641 - Billing Software v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

๐Ÿ“… Published: May 12, 2025, 11:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5451 of 34,919
ยซ previous page ยป next page
Filters