5.3

CVSS4.0

CVE-2025-2626 - SourceCodester Kortex Lite Advocate Office Management System edit_case.php sql injection

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file edit_case.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has …

📅 Published: March 22, 2025, 8:31 p.m. 🔄 Last Modified: April 2, 2025, 2:42 p.m.

5.3

CVSS4.0

CVE-2025-2625 - westboy CicadasCMS page sql injection

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument orderField/orderDirection leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

📅 Published: March 22, 2025, 8 p.m. 🔄 Last Modified: March 27, 2025, 12:36 a.m.

5.3

CVSS4.0

CVE-2025-2624 - westboy CicadasCMS save sql injection

A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/cms/content/save. The manipulation of the argument content/fujian/laiyuan leads to sql injection. The attack may be launched remotely. The exp…

📅 Published: March 22, 2025, 7 p.m. 🔄 Last Modified: March 26, 2025, 6:26 p.m.

5.1

CVSS4.0

CVE-2025-2623 - westboy CicadasCMS save cross site scripting

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyuan leads to cross site scripting. The attack can be launched…

📅 Published: March 22, 2025, 5:31 p.m. 🔄 Last Modified: March 26, 2025, 6:29 p.m.

5.3

CVSS4.0

CVE-2025-2622 - aizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserialization

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the argument nodeExpression leads to deserializati…

📅 Published: March 22, 2025, 5 p.m. 🔄 Last Modified: March 26, 2025, 6:38 p.m.

9.3

CVSS4.0

CVE-2025-2621 - D-Link DAP-1620 storage check_dws_cookie stack-based overflow

A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the…

📅 Published: March 22, 2025, 4:31 p.m. 🔄 Last Modified: March 26, 2025, 6:43 p.m.

9.3

CVSS4.0

CVE-2025-2620 - D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow

A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remo…

📅 Published: March 22, 2025, 2:31 p.m. 🔄 Last Modified: March 26, 2025, 6:44 p.m.

9.3

CVSS4.0

CVE-2025-2619 - D-Link DAP-1620 Cookie storage check_dws_cookie stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit h…

📅 Published: March 22, 2025, 2 p.m. 🔄 Last Modified: March 26, 2025, 6:46 p.m.

9.3

CVSS4.0

CVE-2025-2618 - D-Link DAP-1620 Path api set_ws_action heap-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit…

📅 Published: March 22, 2025, 1:31 p.m. 🔄 Last Modified: March 26, 2025, 6:48 p.m.

7.5

CVSS3.1

CVE-2025-2186 - Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKi…

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and l…

📅 Published: March 22, 2025, 12:42 p.m. 🔄 Last Modified: April 22, 2026, 2 a.m.
Total resulsts: 349182
Page 6251 of 34,919
« previous page » next page
Filters