4.3

CVSS3.1

CVE-2025-1212 - Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitLab

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.

πŸ“… Published: Feb. 12, 2025, 3:02 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 6:48 p.m.

4.9

CVSS3.1

CVE-2025-1042 - Files or Directories Accessible to External Parties in GitLab

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

πŸ“… Published: Feb. 12, 2025, 3:02 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 6:48 p.m.

5.3

CVSS4.0

CVE-2025-1206 - Codezips Gym Management System viewdetailroutine.php sql injection

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /dashboard/admin/viewdetailroutine.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Feb. 12, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 8:39 p.m.

5.3

CVSS4.0

CVE-2025-1202 - SourceCodester Best Church Management Software edit_slider.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best Church Management Software 1.1. Affected is an unknown function of the file /admin/edit_slider.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: Feb. 12, 2025, 2:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:02 p.m.

5.3

CVSS4.0

CVE-2025-1201 - SourceCodester Best Church Management Software profile_crud.php sql injection

A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/app/profile_crud.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Feb. 12, 2025, 2 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:01 p.m.

3.9

CVSS3.1

CVE-2024-23563 - HCL Connections Docs is vulnerable to a sensitive information disclosure

HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

πŸ“… Published: Feb. 12, 2025, 1:47 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:25 p.m.

5.3

CVSS4.0

CVE-2025-1200 - SourceCodester Best Church Management Software slider_crud.php sql injection

A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/app/slider_crud.php. The manipulation of the argument del_id leads to sql injection. The attack can be initiated remotely. Th…

πŸ“… Published: Feb. 12, 2025, 1:31 p.m. πŸ”„ Last Modified: April 29, 2025, 8:24 p.m.

8.8

CVSS3.1

CVE-2025-26378 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: April 10, 2025, 8:25 p.m.

8.1

CVSS3.1

CVE-2025-26377 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-26376 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: April 10, 2025, 7:54 p.m.
Total resulsts: 343984
Page 6241 of 34,399
Β« previous page Β» next page
Filters