5.3

CVSS4.0

CVE-2025-2688 - TOTOLINK A3000RU Syslog Configuration File ExportSyslog.sh access control

A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attackโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: July 2, 2025, 6:03 p.m.

5.3

CVSS4.0

CVE-2025-2687 - PHPGurukul eLearning System Image index.php unrestricted upload

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: March 27, 2025, 6:14 p.m.

3.5

CVSS3.1

CVE-2025-1203 - Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for exampleโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 1:13 p.m.

3.5

CVSS3.1

CVE-2025-1062 - Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example โ€ฆ

๐Ÿ“… Published: March 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 1:20 p.m.

3.5

CVSS3.1

CVE-2024-13124 - Photo Gallery by 10Web < 1.8.33 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 13, 2025, 8:08 p.m.

3.5

CVSS3.1

CVE-2024-10558 - Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 13, 2025, 1:29 p.m.

6.9

CVSS4.0

CVE-2025-2686 - mingyuefusu ๆ˜Žๆœˆๅค่‹ tushuguanlixitong ๅ›พไนฆ็ฎก็†็ณป็ปŸ Backend admin doFilter access control

A vulnerability has been found in mingyuefusu ๆ˜Žๆœˆๅค่‹ tushuguanlixitong ๅ›พไนฆ็ฎก็†็ณป็ปŸ up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leadsโ€ฆ

๐Ÿ“… Published: March 24, 2025, 5:31 a.m. ๐Ÿ”„ Last Modified: March 24, 2025, 3:24 p.m.

6.9

CVSS4.0

CVE-2025-2684 - PHPGurukul Bank Locker Management System search-report-details.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. This issue affects some unknown processing of the file /search-report-details.php. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remoโ€ฆ

๐Ÿ“… Published: March 24, 2025, 5 a.m. ๐Ÿ”„ Last Modified: March 24, 2025, 5:18 p.m.

6.9

CVSS4.0

CVE-2025-2683 - PHPGurukul Bank Locker Management System profile.php sql injection

A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been discloโ€ฆ

๐Ÿ“… Published: March 24, 2025, 4:31 a.m. ๐Ÿ”„ Last Modified: March 27, 2025, 6:14 p.m.

6.9

CVSS4.0

CVE-2025-2682 - PHPGurukul Bank Locker Management System edit-subadmin.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /edit-subadmin.php?said=3. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: March 24, 2025, 4 a.m. ๐Ÿ”„ Last Modified: March 27, 2025, 6:14 p.m.
Total resulsts: 343183
Page 5644 of 34,319
ยซ previous page ยป next page
Filters