5.1

CVSS4.0

CVE-2025-2043 - LinZhaoguan pb-cms Add New Topic admin#themes deserialization

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be initiated remotely. T…

πŸ“… Published: March 6, 2025, 9:31 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:28 a.m.

5.3

CVSS4.0

CVE-2025-2042 - huang-yk student-manage cross-site request forgery

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: March 6, 2025, 9 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 8:21 p.m.

5.3

CVSS4.0

CVE-2025-2041 - s-a-zhd Ecommerce-Website-using-PHP shop.php sql injection

A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The attack may be launched remotely. The exploit h…

πŸ“… Published: March 6, 2025, 8:31 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 8:31 p.m.

5.3

CVSS4.0

CVE-2025-2040 - zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can …

πŸ“… Published: March 6, 2025, 8 p.m. πŸ”„ Last Modified: July 7, 2025, 6:29 p.m.

5.1

CVSS4.0

CVE-2025-2039 - code-projects Blood Bank Management System delete_members.php sql injection

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The manipulation of the argument member_id leads to sql injection. It is possible to launch the attack remotely. The exploi…

πŸ“… Published: March 6, 2025, 8 p.m. πŸ”„ Last Modified: May 13, 2025, 8:57 p.m.

6.9

CVSS4.0

CVE-2025-2038 - code-projects Blood Bank Management System upload exposure of information through directory listing

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The exploit…

πŸ“… Published: March 6, 2025, 7:31 p.m. πŸ”„ Last Modified: May 13, 2025, 8:57 p.m.

6.9

CVSS4.0

CVE-2025-27600 - FastGPT SSRF

FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an intranet IP request, causing the system to initiate a request through the intranet and potentially obtain some private data on the intranet.…

πŸ“… Published: March 6, 2025, 7:05 p.m. πŸ”„ Last Modified: March 6, 2025, 8:04 p.m.

9.3

CVSS4.0

CVE-2025-27509 - SAML authentication vulnerability due to improper SAML response validation

fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new…

πŸ“… Published: March 6, 2025, 7 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-2037 - code-projects Blood Bank Management System delete_requester.php sql injection

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_dashboard/delete_requester.php. The manipulation of the argument requester_id leads to sql injection. The attack can be initiated …

πŸ“… Published: March 6, 2025, 7 p.m. πŸ”„ Last Modified: May 13, 2025, 8:58 p.m.

5.4

CVSS3.1

CVE-2025-27506 - NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementa…

πŸ“… Published: March 6, 2025, 6:52 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:52 p.m.
Total resulsts: 343975
Page 5906 of 34,398
Β« previous page Β» next page
Filters