5.4

CVSS3.1

CVE-2025-45751 -

SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 7:16 p.m.

9.8

CVSS3.1

CVE-2025-45612 -

Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2025-45610 -

Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 7:01 p.m.

7.5

CVSS3.1

CVE-2025-45320 -

A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2025-45237 -

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 7:55 p.m.

6.5

CVSS3.1

CVE-2025-45618 -

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 21, 2025, 3:38 p.m.

7.5

CVSS3.1

CVE-2025-45614 -

Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-45609 -

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 7:05 p.m.

9.8

CVSS3.1

CVE-2025-45607 -

An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 8:17 p.m.

7.2

CVSS3.1

CVE-2025-27920 -

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:28 p.m.
Total resulsts: 348395
Page 5480 of 34,840
ยซ previous page ยป next page
Filters