6.4

CVSS3.1

CVE-2025-32413 -

Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.

๐Ÿ“… Published: April 8, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-3389 - hailey888 oa_system Backend InformManageController.java testMess cross site scripting

A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to croโ€ฆ

๐Ÿ“… Published: April 7, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: May 7, 2025, 4:59 p.m.

5.3

CVSS4.0

CVE-2025-3388 - hailey888 oa_system Frontend LoginsController.java loginCheck cross site scripting

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site sโ€ฆ

๐Ÿ“… Published: April 7, 2025, 11 p.m. ๐Ÿ”„ Last Modified: May 7, 2025, 4:51 p.m.

5.1

CVSS4.0

CVE-2025-3387 - renrenio renren-security JSON cross site scripting

A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public โ€ฆ

๐Ÿ“… Published: April 7, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:20 p.m.

4.8

CVSS4.0

CVE-2025-3386 - LinZhaoguan pb-cms Friendship Link admin#links cross site scripting

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The expโ€ฆ

๐Ÿ“… Published: April 7, 2025, 10 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:20 p.m.

8.6

CVSS3.1

CVE-2025-0942 - Jalios JPlatform 10 SP6 < 10.0.6 Record Chooser SQL Injection

The DB chooser functionality inย Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.

๐Ÿ“… Published: April 7, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-3385 - LinZhaoguan pb-cms Classification Management Page cross site scripting

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Classification Management Page. The manipulation of the argument Classification name leads to cross site scripting. The attack can beโ€ฆ

๐Ÿ“… Published: April 7, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:19 p.m.

6.9

CVSS4.0

CVE-2025-3384 - 1000 Projects Human Resource Management System employee.php sql injection

A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /controller/employee.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. Theโ€ฆ

๐Ÿ“… Published: April 7, 2025, 9 p.m. ๐Ÿ”„ Last Modified: April 9, 2025, 2:44 p.m.

7.5

CVSS3.1

CVE-2025-32034 - Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansiโ€ฆ

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, a vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensivโ€ฆ

๐Ÿ“… Published: April 7, 2025, 8:50 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-32033 - Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, the operation limits plugin uses unsigned 32-bit integers to track limit counters (e.g. for a query's height). If a counterโ€ฆ

๐Ÿ“… Published: April 7, 2025, 8:48 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345149
Page 5578 of 34,515
ยซ previous page ยป next page
Filters