9.3

CVSS4.0

CVE-2025-27519 - Cognita Arbitrary File Write

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at /v1/internal/upload-to-local-directory which is enabled when the Local env variable is set to true, such as when Cognita is setu…

📅 Published: March 7, 2025, 3:36 p.m. 🔄 Last Modified: March 7, 2025, 9:48 p.m.

7.7

CVSS4.0

CVE-2025-27152 - Possible SSRF and Credential Leakage via Absolute URL in axios Requests

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impa…

📅 Published: March 7, 2025, 3:13 p.m. 🔄 Last Modified: Nov. 25, 2025, 5:58 p.m.

5.1

CVSS4.0

CVE-2025-2090 - PHPGurukul Pre-School Enrollment System Sub Admin add-subadmin.php access control

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php of the component Sub Admin Handler. The manipulation leads to improper access controls. The attack may be lau…

📅 Published: March 7, 2025, 3 p.m. 🔄 Last Modified: April 3, 2025, 1:33 p.m.

5.3

CVSS4.0

CVE-2025-2089 - StarSea99 starsea-mall com.siro.mall.controller.mall.UserController updateInfo updateUserInfo acces…

A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the component com.siro.mall.controller.mall.UserController. The manipulation of the argument userId leads to…

📅 Published: March 7, 2025, 3 p.m. 🔄 Last Modified: Oct. 10, 2025, 7:09 p.m.

6.9

CVSS4.0

CVE-2025-2088 - PHPGurukul Pre-School Enrollment System profile.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of the file /admin/profile.php. The manipulation of the argument fullname/emailid/mobileNumber leads to sql injection. It is possible to launch the atta…

📅 Published: March 7, 2025, 2:31 p.m. 🔄 Last Modified: March 13, 2025, 3:53 p.m.

5.1

CVSS4.0

CVE-2025-2087 - StarSea99 starsea-mall update cross site scripting

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site scripting. The attack may be initiated remotely. The exploit…

📅 Published: March 7, 2025, 2 p.m. 🔄 Last Modified: March 13, 2025, 3:57 p.m.

5.1

CVSS4.0

CVE-2025-2086 - StarSea99 starsea-mall update cross site scripting

A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown code of the file /admin/indexConfigs/update. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be initiated remotely. The exploit has been d…

📅 Published: March 7, 2025, 2 p.m. 🔄 Last Modified: March 13, 2025, 4:05 p.m.

5.1

CVSS4.0

CVE-2025-2085 - StarSea99 starsea-mall save cross site scripting

A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of the file /admin/carousels/save. The manipulation of the argument redirectUrl leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been di…

📅 Published: March 7, 2025, noon 🔄 Last Modified: March 13, 2025, 3:23 p.m.

5.1

CVSS4.0

CVE-2025-2084 - PHPGurukul Human Metapneumovirus Testing Management System Search Report Page search-report.php cro…

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /search-report.php of the component Search Report Page. The manipulation leads to cross site scripting. It is possible to l…

📅 Published: March 7, 2025, noon 🔄 Last Modified: March 12, 2025, 5:20 p.m.

6.1

CVSS3.1

CVE-2024-12634 - Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.…

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthent…

📅 Published: March 7, 2025, 11:12 a.m. 🔄 Last Modified: March 7, 2025, 2:35 p.m.
Total resulsts: 343924
Page 5892 of 34,393
« previous page » next page
Filters