6.9

CVSS4.0

CVE-2025-4027 - PHPGurukul Old Age Home Management System rules.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit h…

πŸ“… Published: April 28, 2025, 4 p.m. πŸ”„ Last Modified: April 30, 2025, 6:11 p.m.

2.3

CVSS4.0

CVE-2025-43854 - DIFY vulnerable to Clickjacking Attack

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to u…

πŸ“… Published: April 28, 2025, 3:58 p.m. πŸ”„ Last Modified: May 12, 2025, 7:37 p.m.

6.9

CVSS4.0

CVE-2025-4026 - PHPGurukul Nipah Virus Testing Management System profile.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname/mobilenumber leads to sql injection. The attack may be initiated…

πŸ“… Published: April 28, 2025, 3:31 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:50 p.m.

0.0

CVE-2025-4042 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: April 28, 2025, 3:31 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 10:19 p.m.

6.9

CVSS4.0

CVE-2025-4025 - itsourcecode Placement Management System registration.php sql injection

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit …

πŸ“… Published: April 28, 2025, 3 p.m. πŸ”„ Last Modified: April 30, 2025, 7:52 p.m.

4.2

CVSS3.1

CVE-2025-23377 -

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.

πŸ“… Published: April 28, 2025, 2:38 p.m. πŸ”„ Last Modified: May 13, 2025, 1:25 p.m.

2.3

CVSS3.1

CVE-2025-23376 -

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

πŸ“… Published: April 28, 2025, 2:34 p.m. πŸ”„ Last Modified: May 13, 2025, 1:25 p.m.

6.9

CVSS4.0

CVE-2025-4024 - itsourcecode Placement Management System add_drive.php sql injection

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: April 28, 2025, 2:31 p.m. πŸ”„ Last Modified: April 30, 2025, 7:55 p.m.

7.8

CVSS3.1

CVE-2025-23375 -

Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: April 28, 2025, 2:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.9

CVSS4.0

CVE-2025-4023 - itsourcecode Placement Management System add_company.php sql injection

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: April 28, 2025, 2 p.m. πŸ”„ Last Modified: May 14, 2025, 7:02 p.m.
Total resulsts: 349182
Page 5645 of 34,919
Β« previous page Β» next page
Filters