3.5

CVSS3.1

CVE-2025-46350 - Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the userโ€™s session. This vulnerability maโ€ฆ

๐Ÿ“… Published: April 29, 2025, 5:11 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:57 p.m.

7.6

CVSS3.1

CVE-2025-46349 - YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patchโ€ฆ

๐Ÿ“… Published: April 29, 2025, 5:11 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:56 p.m.

5.8

CVSS4.0

CVE-2025-46347 - YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of thโ€ฆ

๐Ÿ“… Published: April 29, 2025, 5:11 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:56 p.m.

6.9

CVSS4.0

CVE-2025-4073 - PHPGurukul Student Record System change-password.php sql injection

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: April 29, 2025, 5 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:51 p.m.

5.3

CVSS4.0

CVE-2025-4072 - PHPGurukul Online Nurse Hiring System edit-nurse.php sql injection

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the publiโ€ฆ

๐Ÿ“… Published: April 29, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:51 p.m.

4.8

CVSS3.1

CVE-2025-0716 - AngularJS improper sanitization in SVG '<image>' element

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing ย and also negativelyโ€ฆ

๐Ÿ“… Published: April 29, 2025, 4:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2025-23181 - Ribbon Communications - CWE-250: Execution with Unnecessary Privileges

CWE-250: Execution with Unnecessary Privileges

๐Ÿ“… Published: April 29, 2025, 4:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2025-23180 - Ribbon Communications - CWE-250: Execution with Unnecessary Privileges

CWE-250: Execution with Unnecessary Privileges

๐Ÿ“… Published: April 29, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-23179 - Ribbon Communications - CWE-798: Use of Hard-coded Credentials

CWE-798: Use of Hard-coded Credentials

๐Ÿ“… Published: April 29, 2025, 4:09 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-23178 - Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

๐Ÿ“… Published: April 29, 2025, 4:05 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347748
Page 5490 of 34,775
ยซ previous page ยป next page
Filters