5.3

CVSS4.0

CVE-2025-3210 - code-projects Patient Record Management System birthing_pending.php sql injection

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remote…

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: April 8, 2025, 5:43 p.m.

8.8

CVSS4.0

CVE-2025-3192 -

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3209 - code-projects Patient Record Management System add_patient.php sql injection

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_patient.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remo…

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: May 28, 2025, 4:07 p.m.

5.1

CVSS4.0

CVE-2025-3191 -

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-3197 -

Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-3194 -

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

πŸ“… Published: April 4, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3208 - code-projects Patient Record Management System xray_print.php sql injection

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit…

πŸ“… Published: April 4, 2025, 4:31 a.m. πŸ”„ Last Modified: April 8, 2025, 5:48 p.m.

8.1

CVSS3.1

CVE-2024-13744 - Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

πŸ“… Published: April 4, 2025, 4:21 a.m. πŸ”„ Last Modified: April 9, 2025, 6:09 p.m.

8.8

CVSS3.1

CVE-2025-2075 - Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escal…

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the vali…

πŸ“… Published: April 4, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.

5.3

CVSS4.0

CVE-2025-3207 - code-projects Patient Record Management System birthing_form.php sql injection

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /birthing_form.php. The manipulation of the argument birth_id leads to sql injection. The attack may be initiated remotely. The exploit …

πŸ“… Published: April 4, 2025, 4 a.m. πŸ”„ Last Modified: April 8, 2025, 5:56 p.m.
Total resulsts: 344963
Page 5603 of 34,497
Β« previous page Β» next page
Filters