6.9

CVSS4.0

CVE-2025-3176 - Project Worlds Online Lawyer Management System single_lawyer.php sql injection

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: April 3, 2025, 7:31 p.m. πŸ”„ Last Modified: May 15, 2025, 8:06 p.m.

7.5

CVSS3.1

CVE-2025-31481 - GraphQL query operations security can be bypassed

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

πŸ“… Published: April 3, 2025, 7:20 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.7

CVSS3.1

CVE-2025-31119 - CWE-470 in generator-jhipster-entity-audit when having Javers selected as Entity Audit Framework

generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath a…

πŸ“… Published: April 3, 2025, 7:11 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3175 - Project Worlds Online Lawyer Management System save_user_edit_profile.php sql injection

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The attack may be launched re…

πŸ“… Published: April 3, 2025, 7 p.m. πŸ”„ Last Modified: May 15, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-3174 - Project Worlds Online Lawyer Management System searchLawyer.php sql injection

A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to sql injection. The attack can be launched r…

πŸ“… Published: April 3, 2025, 7 p.m. πŸ”„ Last Modified: April 23, 2025, 3:02 p.m.

7.7

CVSS3.1

CVE-2025-31487 - The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server

The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns an XML specifying a …

πŸ“… Published: April 3, 2025, 6:38 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3173 - Project Worlds Online Lawyer Management System save_booking.php sql injection

A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id/description leads to sql injection. It is possible to launch the attack remot…

πŸ“… Published: April 3, 2025, 6:31 p.m. πŸ”„ Last Modified: Sept. 27, 2025, 12:33 a.m.

5.3

CVSS3.1

CVE-2025-31486 - Vite allows server.fs.deny to be bypassed with .svg or relative paths

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than bu…

πŸ“… Published: April 3, 2025, 6:24 p.m. πŸ”„ Last Modified: July 13, 2025, 11:06 a.m.

4.8

CVSS4.0

CVE-2025-31483 - Stored XSS in Miniflux Media Proxy due to improper Content-Security-Policy configuration

Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy has been changed fr…

πŸ“… Published: April 3, 2025, 6:07 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3172 - Project Worlds Online Lawyer Management System lawyer_booking.php sql injection

A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyer_booking.php. The manipulation of the argument unblock_id leads to sql injection. The attack may be initiated remote…

πŸ“… Published: April 3, 2025, 6 p.m. πŸ”„ Last Modified: May 15, 2025, 8:07 p.m.
Total resulsts: 343932
Page 5505 of 34,394
Β« previous page Β» next page
Filters