5.3
CVE-2025-1210 - code-projects Wazifa System control.php sql injection
A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been…
5.1
CVE-2025-1209 - code-projects Wazifa System search_resualts.php searchuser cross site scripting
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exp…
7.1
CVE-2024-11629 - Telerik Document Processing RTF Export of Arbitrary File Path
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
5.7
CVE-2025-25184 - Possible Log Injection in Rack::CommonLogger
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content …
4.1
CVE-2024-11628 - Prototype Pollution in Progress® Telerik® Kendo UI for Vue
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
9.4
CVE-2025-25182 - Stroom Authentication/Authorization Bypass when using AWS ALB
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the applicati…
0.0
CVE-2025-1256 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.1
CVE-2025-1208 - code-projects Wazifa System Profile.php cross site scripting
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
8.3
CVE-2024-11343 - Telerik Document Processing Path Traversal
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.
4.1
CVE-2024-12629 - Prototype Pollution in Progress® Telerik® KendoReact
In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.