6.9

CVSS4.0

CVE-2025-4025 - itsourcecode Placement Management System registration.php sql injection

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit …

πŸ“… Published: April 28, 2025, 3 p.m. πŸ”„ Last Modified: April 30, 2025, 7:52 p.m.

4.2

CVSS3.1

CVE-2025-23377 -

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.

πŸ“… Published: April 28, 2025, 2:38 p.m. πŸ”„ Last Modified: May 13, 2025, 1:25 p.m.

2.3

CVSS3.1

CVE-2025-23376 -

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

πŸ“… Published: April 28, 2025, 2:34 p.m. πŸ”„ Last Modified: May 13, 2025, 1:25 p.m.

6.9

CVSS4.0

CVE-2025-4024 - itsourcecode Placement Management System add_drive.php sql injection

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: April 28, 2025, 2:31 p.m. πŸ”„ Last Modified: April 30, 2025, 7:55 p.m.

7.8

CVSS3.1

CVE-2025-23375 -

Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: April 28, 2025, 2:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.9

CVSS4.0

CVE-2025-4023 - itsourcecode Placement Management System add_company.php sql injection

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: April 28, 2025, 2 p.m. πŸ”„ Last Modified: May 14, 2025, 7:02 p.m.

5.3

CVSS4.0

CVE-2025-4022 - web-arena-x webarena evaluators.py HTMLContentEvaluator code injection

A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["url"] leads to code injection. The attack can…

πŸ“… Published: April 28, 2025, 1:31 p.m. πŸ”„ Last Modified: May 14, 2025, 7:32 p.m.

5.3

CVSS4.0

CVE-2025-4021 - code-projects Patient Record Management System edit_spatient.php sql injection

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit h…

πŸ“… Published: April 28, 2025, 1 p.m. πŸ”„ Last Modified: May 14, 2025, 7:34 p.m.

6.9

CVSS4.0

CVE-2025-4020 - PHPGurukul Old Age Home Management System contact.php sql injection

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has b…

πŸ“… Published: April 28, 2025, 12:31 p.m. πŸ”„ Last Modified: April 30, 2025, 6:18 p.m.

5.3

CVSS3.1

CVE-2025-32472 - DoS attack by conducting a slowloris-type attack

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive.

πŸ“… Published: April 28, 2025, 12:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347438
Page 5471 of 34,744
Β« previous page Β» next page
Filters