4.8

CVSS4.0

CVE-2025-3821 - SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The …

πŸ“… Published: April 20, 2025, 4 a.m. πŸ”„ Last Modified: April 24, 2025, 3:43 p.m.

5.8

CVSS3.1

CVE-2025-43928 -

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 4 p.m.

2.9

CVSS3.1

CVE-2025-43967 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 4:05 p.m.

4.9

CVSS3.1

CVE-2025-43954 -

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 4:49 p.m.

2.2

CVSS3.1

CVE-2025-43955 -

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 2:26 p.m.

2.9

CVSS3.1

CVE-2025-43966 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 4:03 p.m.

2.9

CVSS3.1

CVE-2025-43963 - LibRaw: out-of-buffer access

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

4.1

CVSS3.1

CVE-2025-43929 -

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 3:46 p.m.

2.9

CVSS3.1

CVE-2025-43961 - LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

5.8

CVSS3.1

CVE-2025-43919 -

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable…

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 28, 2025, 2:15 p.m.
Total resulsts: 346617
Page 5455 of 34,662
Β« previous page Β» next page
Filters