6.9

CVSS4.0

CVE-2025-3138 - PHPGurukul Online Security Guards Hiring System edit-guard-detail.php sql injection

A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be la…

πŸ“… Published: April 3, 2025, 4 a.m. πŸ”„ Last Modified: April 9, 2025, 8:17 p.m.

6.9

CVSS4.0

CVE-2025-3137 - PHPGurukul Online Security Guards Hiring System changeimage.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The …

πŸ“… Published: April 3, 2025, 3:31 a.m. πŸ”„ Last Modified: April 9, 2025, 8:28 p.m.

4.8

CVSS4.0

CVE-2025-3136 - PyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruption

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The e…

πŸ“… Published: April 3, 2025, 3:31 a.m. πŸ”„ Last Modified: May 28, 2025, 3:59 p.m.

5.3

CVSS4.0

CVE-2025-3135 - fcba_zzm ics-park Smart Park Management System update sql injection

A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the p…

πŸ“… Published: April 3, 2025, 1:31 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 2:43 p.m.

5.3

CVSS4.0

CVE-2025-3134 - code-projects Payroll Management System add_overtime.php sql injection

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: April 3, 2025, 1:31 a.m. πŸ”„ Last Modified: May 14, 2025, 4:26 p.m.

5.1

CVSS4.0

CVE-2025-3153 - Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Cust…

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified.Β  Attackers are limited to individuals whom a site administrator has grante…

πŸ“… Published: April 3, 2025, 12:17 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:54 p.m.

8.8

CVSS3.1

CVE-2024-45198 -

insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-32053 - Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()

A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.2

CVSS3.1

CVE-2025-29991 -

Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-22927 -

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 6:18 p.m.
Total resulsts: 349182
Page 6041 of 34,919
Β« previous page Β» next page
Filters