7.6

CVSS3.1

CVE-2025-29189 -

Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 5:11 p.m.

8.1

CVSS3.1

CVE-2025-29394 -

An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-32464 - haproxy: Buffer Overflow via Improper Back-Reference Replacement Length Check

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-29390 -

jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 5:06 p.m.

7.2

CVSS3.1

CVE-2025-29391 -

horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 5:02 p.m.

9.9

CVSS3.1

CVE-2025-32461 -

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-55210 -

An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 7:09 p.m.

4

CVSS3.1

CVE-2025-32460 -

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 8:34 p.m.

4.8

CVSS3.1

CVE-2025-29018 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.

๐Ÿ“… Published: April 9, 2025, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 6:47 p.m.

6.5

CVSS3.1

CVE-2025-25013 - Elastic Defend Insertion of Sensitive Information into Log Files

Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.

๐Ÿ“… Published: April 8, 2025, 10:16 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346614
Page 5689 of 34,662
ยซ previous page ยป next page
Filters