3.4

CVSS3.1

CVE-2025-43916 -

Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC 6819 section 5.2.3.5. An authorization code may be sent to an attacker-controlled destination. This might have f…

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-42699 -

Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 4:42 p.m.

9.8

CVSS3.1

CVE-2025-29660 -

A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traver…

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 1:40 p.m.

3.3

CVSS3.1

CVE-2025-29446 -

open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 3:49 p.m.

5.4

CVSS3.1

CVE-2024-41446 -

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 4:44 p.m.

9.8

CVSS3.1

CVE-2025-29659 -

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

πŸ“… Published: April 21, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 1:42 p.m.

5.3

CVSS4.0

CVE-2025-3830 - kuangstudy KuangSimpleBBS QuestionController.java fileUpload unrestricted upload

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file src/main/java/com/kuang/controller/QuestionController.java. The manipulation of the argument editormd-image-file leads to unrestricted …

πŸ“… Published: April 20, 2025, 4:31 p.m. πŸ”„ Last Modified: April 30, 2025, 5:07 p.m.

6.9

CVSS4.0

CVE-2025-3829 - PHPGurukul Men Salon Management System sales-reports-detail.php sql injection

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remo…

πŸ“… Published: April 20, 2025, 4 p.m. πŸ”„ Last Modified: April 28, 2025, 5:38 p.m.

6.9

CVSS4.0

CVE-2025-3828 - PHPGurukul Men Salon Management System view-appointment.php sql injection

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injection. The attack may be initiated remotely. The…

πŸ“… Published: April 20, 2025, 3:31 p.m. πŸ”„ Last Modified: April 28, 2025, 5:38 p.m.

6.9

CVSS4.0

CVE-2025-3827 - PHPGurukul Men Salon Management System forgot-password.php sql injection

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit h…

πŸ“… Published: April 20, 2025, 3 p.m. πŸ”„ Last Modified: April 28, 2025, 5:38 p.m.
Total resulsts: 349182
Page 5710 of 34,919
Β« previous page Β» next page
Filters