6.9

CVSS4.0

CVE-2025-2243 - SSRF in GravityZone Console via DNS Truncation (VA-12634)

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests. Paired with other potential vulnerabilities, this bypass could be used for execution of third party code. This issue af…

📅 Published: April 4, 2025, 9:53 a.m. 🔄 Last Modified: July 30, 2025, 7:04 p.m.

8.5

CVSS4.0

CVE-2025-1865 - Local Privilege Escalation in Virtual CloneDrive Kernel Driver

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

📅 Published: April 4, 2025, 9:52 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.5

CVSS4.0

CVE-2025-2244 - Insecure PHP deserialization issue in GravityZone Console (VA-12634)

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write,…

📅 Published: April 4, 2025, 9:52 a.m. 🔄 Last Modified: July 30, 2025, 7:04 p.m.

6.9

CVSS4.0

CVE-2025-3236 - Tenda FH1202 Web Management Interface VirSerDMZ access control

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The e…

📅 Published: April 4, 2025, 9:31 a.m. 🔄 Last Modified: May 28, 2025, 2:46 p.m.

5.3

CVSS4.0

CVE-2025-3235 - PHPGurukul Old Age Home Management System profile.php sql injection

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/profile.php. The manipulation of the argument adminname/contactnumber leads to sql injection. It is possible to initiate the attack remotel…

📅 Published: April 4, 2025, 9:31 a.m. 🔄 Last Modified: May 16, 2025, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-3231 - PHPGurukul Zoo Management System aboutus.php sql injection

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /aboutus.php. The manipulation of the argument pagetitle/pagedes leads to sql injection. The attack may be initiated remotely. The exploit has bee…

📅 Published: April 4, 2025, 9 a.m. 🔄 Last Modified: Sept. 27, 2025, 12:34 a.m.

5.1

CVSS4.0

CVE-2025-3229 - PHPGurukul Restaurant Table Booking System edit-subadmin.php sql injection

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-subadmin.php. The manipulation of the argument fullname leads to sql injection. The attack can be initiated remotely. The exploit …

📅 Published: April 4, 2025, 8:31 a.m. 🔄 Last Modified: May 16, 2025, 3:50 p.m.

6.9

CVSS4.0

CVE-2025-3220 - PHPGurukul e-Diary Management System dashboard.php sql injection

A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The …

📅 Published: April 4, 2025, 8 a.m. 🔄 Last Modified: May 8, 2025, 7:08 p.m.

5.1

CVSS4.0

CVE-2025-3219 - CodeCanyon Perfex CRM Project Discussions Module 2 cross site scripting

A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the component Project Discussions Module. The manipulation of the argument description leads to cross site scripting. It is possi…

📅 Published: April 4, 2025, 7:31 a.m. 🔄 Last Modified: Oct. 2, 2025, 3:35 p.m.

8.8

CVSS3.1

CVE-2025-3105 - Vehica Core <= 1.0.97 - Authenticated (Subscriber+) Privilege Escalation

The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes …

📅 Published: April 4, 2025, 7:27 a.m. 🔄 Last Modified: April 22, 2026, 5:45 p.m.
Total resulsts: 346442
Page 5748 of 34,645
« previous page » next page
Filters