6.8

CVSS4.0

CVE-2025-1534 - Cross-site Scripting (Stored)

CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, fr…

📅 Published: April 1, 2025, 3:25 a.m. 🔄 Last Modified: Oct. 14, 2025, 5:25 p.m.

6.5

CVSS3.1

CVE-2025-3051 - Linux::Statm::Tiny for Perl allows untrusted code to be included from the current working directory

Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary co…

📅 Published: April 1, 2025, 2:20 a.m. 🔄 Last Modified: April 1, 2025, 8:26 p.m.

6.5

CVSS3.1

CVE-2025-30673 - Sub::HandlesVia for Perl allows untrusted code to be included from the current working directory

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary cod…

📅 Published: April 1, 2025, 2:02 a.m. 🔄 Last Modified: April 1, 2025, 8:26 p.m.

6.5

CVSS3.1

CVE-2025-30672 - Mite for Perl generates code with an untrusted search path vulnerability

Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code exec…

📅 Published: April 1, 2025, 1:51 a.m. 🔄 Last Modified: April 1, 2025, 8:26 p.m.

8.3

CVSS3.1

CVE-2025-21384 - Azure Health Bot Elevation of Privilege Vulnerability

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

📅 Published: April 1, 2025, 12:40 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS4.0

CVE-2025-3045 - oretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injection

A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /remove-apartment.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remote…

📅 Published: April 1, 2025, 12:31 a.m. 🔄 Last Modified: May 27, 2025, 6:53 p.m.

6.9

CVSS4.0

CVE-2025-3043 - GuoMinJim PersonManage login preHandle path traversal

A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the file /login/. The manipulation of the argument Request leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to t…

📅 Published: April 1, 2025, 12:31 a.m. 🔄 Last Modified: April 1, 2025, 8:26 p.m.

5.3

CVSS4.0

CVE-2025-3042 - Project Worlds Online Time Table Generator updateprofile.php unrestricted upload

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the file /student/updateprofile.php. The manipulation of the argument pic leads to unrestricted upload. The attack can be initiated remotely. The exploit ha…

📅 Published: April 1, 2025, midnight 🔄 Last Modified: July 9, 2025, 3:38 p.m.

8.1

CVSS3.1

CVE-2025-21947 - ksmbd: fix type confusion via race condition when using ipc_msg_send_request

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on ida_alloc. req->handle from ksmbd_ipc_login_request and FSCTL_PIPE_TRANSCEIVE ioctl …

📅 Published: April 1, 2025, midnight 🔄 Last Modified: April 2, 2026, 8:39 a.m.

5.5

CVSS3.1

CVE-2025-21944 - ksmbd: fix bug on trap in smb2_lock

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix bug on trap in smb2_lock If lock count is greater than 1, flags could be old value. It should be checked with flags of smb_lock, not flags. It will cause bug-on trap from locks_free_lock in error handling routine.

📅 Published: April 1, 2025, midnight 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 343919
Page 5562 of 34,392
« previous page » next page
Filters