5.3

CVSS4.0

CVE-2025-2847 - Codezips Gym Management System over_month.php sql injection

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. The attack may be initiated remotely. The expl…

πŸ“… Published: March 27, 2025, 1 p.m. πŸ”„ Last Modified: May 28, 2025, 6:33 p.m.

3.7

CVSS3.1

CVE-2024-9773 - Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious…

πŸ“… Published: March 27, 2025, 12:31 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 1:20 a.m.

8.7

CVSS3.1

CVE-2025-0811 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

πŸ“… Published: March 27, 2025, 12:31 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 1:14 a.m.

6.9

CVSS4.0

CVE-2025-2846 - SourceCodester Online Eyewear Shop Registration Users.php registration sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argument ID leads to sql injection. The attack c…

πŸ“… Published: March 27, 2025, 12:31 p.m. πŸ”„ Last Modified: May 14, 2025, 9:06 p.m.

7.5

CVSS3.1

CVE-2025-2242 - Incorrect Authorization in GitLab

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to g…

πŸ“… Published: March 27, 2025, 12:30 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 1:13 a.m.

8.7

CVSS3.1

CVE-2025-2255 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

πŸ“… Published: March 27, 2025, 12:30 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 1:11 a.m.

2.7

CVSS3.1

CVE-2025-31141 -

In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

πŸ“… Published: March 27, 2025, 11:24 a.m. πŸ”„ Last Modified: May 16, 2025, 2:51 p.m.

4.6

CVSS3.1

CVE-2025-31140 -

In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page

πŸ“… Published: March 27, 2025, 11:24 a.m. πŸ”„ Last Modified: May 16, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2025-31139 -

In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log

πŸ“… Published: March 27, 2025, 11:24 a.m. πŸ”„ Last Modified: May 16, 2025, 2:51 p.m.

6.5

CVSS3.1

CVE-2025-30925 - WordPress The Pack Elementor addons plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons the-pack-addon allows Stored XSS.This issue affects The Pack Elementor addons: from n/a through <= 2.1.1.

πŸ“… Published: March 27, 2025, 10:56 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.
Total resulsts: 349182
Page 6168 of 34,919
Β« previous page Β» next page
Filters