10

CVSS4.0

CVE-2025-26611 - SQL Injection endpoint 'remover_produto.php' parameter 'id_produto' in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized a…

πŸ“… Published: Feb. 18, 2025, 8:34 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2025-26612 - SQL Injection endpoint 'adicionar_almoxarife.php' parameter 'id_almoxarifado', 'id_funcionario' in …

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthori…

πŸ“… Published: Feb. 18, 2025, 8:34 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2025-26613 - OS Command Injection endpoint 'gerenciar_backup.php' parameter 'file' (RCE) in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. This issue h…

πŸ“… Published: Feb. 18, 2025, 8:33 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

9.4

CVSS4.0

CVE-2025-26614 - SQL Injection endpoint 'deletar_documento.php' parameter 'id_cargo' in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_documento.php` endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access …

πŸ“… Published: Feb. 18, 2025, 8:32 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS3.1

CVE-2025-26615 - Path Traversal endpoint 'examples.php' parameter 'src' in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information stored in …

πŸ“… Published: Feb. 18, 2025, 8:32 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

0.0

CVE-2025-1460 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Feb. 18, 2025, 8:30 p.m. πŸ”„ Last Modified: Feb. 26, 2025, 11:15 p.m.

10

CVSS4.0

CVE-2025-26616 - Path Traversal endpoint 'exportar_dump.php' parameter 'file' in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information store…

πŸ“… Published: Feb. 18, 2025, 8:30 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2025-26617 - SQL Injection endpoint 'historico_paciente.php' parameter 'id_fichamedica' in WeGIA

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorize…

πŸ“… Published: Feb. 18, 2025, 8:29 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

0.0

CVE-2025-22663 - WordPress Paid Videochat Turnkey Site plugin <= 7.2.12 - Arbitrary File Deletion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Path Traversal.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.2.12.

πŸ“… Published: Feb. 18, 2025, 7:54 p.m. πŸ”„ Last Modified: April 1, 2026, 4:22 p.m.

0.0

CVE-2025-22657 - WordPress Atarim plugin <= 4.0.9 - Arbitrary Content Deletion vulnerability

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.0.9.

πŸ“… Published: Feb. 18, 2025, 7:54 p.m. πŸ”„ Last Modified: April 1, 2026, 4:22 p.m.
Total resulsts: 343935
Page 6170 of 34,394
Β« previous page Β» next page
Filters