5.4
CVE-2025-45751 -
SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.
9.8
CVE-2025-45612 -
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
7.5
CVE-2025-45610 -
Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.
7.5
CVE-2025-45320 -
A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.
7.5
CVE-2025-45237 -
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
6.5
CVE-2025-45618 -
Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.
7.5
CVE-2025-45614 -
Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.
7.5
CVE-2025-45609 -
Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.
9.8
CVE-2025-45607 -
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.
7.2
CVE-2025-27920 -
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.