5.3

CVSS4.0

CVE-2025-1162 - code-projects Job Recruitment load\_user-profile.php sql injection

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of the argument userhash leads to sql injection. It is possible to initiate the attack remotely. The exploit has bee…

πŸ“… Published: Feb. 10, 2025, 11 p.m. πŸ”„ Last Modified: May 28, 2025, 5:22 p.m.

6.9

CVSS4.0

CVE-2025-1160 - SourceCodester Employee Management System index.php default credentials

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The attack may be launched r…

πŸ“… Published: Feb. 10, 2025, 10:31 p.m. πŸ”„ Last Modified: March 3, 2025, 4:52 p.m.

4

CVSS3.1

CVE-2025-25194 - Server-Side Request Forgery (SSRF) in activitypub_federation

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19…

πŸ“… Published: Feb. 10, 2025, 10:14 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 3:19 p.m.

5.5

CVSS4.0

CVE-2025-25190 - [XBOW-025-033] Cross-Site Scripting (XSS) via EchoProcess Service in ZOO-Project WPS Server

The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cross-Site Scripting (XSS) vulnerability in its EchoProcess service prior to commit 7a5ae1a. The vulnerability exists because the EchoProcess service directly reflects user input in…

πŸ“… Published: Feb. 10, 2025, 10:11 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 4:15 p.m.

5.5

CVSS4.0

CVE-2025-25189 - [XBOW-025-031] Reflected Cross-Site Scripting via jobid Parameter in ZOO-Project WPS publish.py CGI…

The ZOO-Project is an open source processing platform. A reflected Cross-Site Scripting vulnerability exists in the ZOO-Project Web Processing Service (WPS) publish.py CGI script prior to commit 7a5ae1a. The script reflects user input from the `jobid` parameter in its HTTP response without proper H…

πŸ“… Published: Feb. 10, 2025, 10:05 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2025-25193 - Denial of Service attack on windows app using Netty

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file tha…

πŸ“… Published: Feb. 10, 2025, 10:02 p.m. πŸ”„ Last Modified: June 11, 2025, 3:36 p.m.

5.1

CVSS4.0

CVE-2025-1159 - CampCodes School Management Software academic-calendar cross site scripting

A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has…

πŸ“… Published: Feb. 10, 2025, 10 p.m. πŸ”„ Last Modified: March 28, 2025, 6:27 p.m.

7.5

CVSS3.1

CVE-2025-24970 - SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLE…

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead t…

πŸ“… Published: Feb. 10, 2025, 9:57 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 5:20 p.m.

5.3

CVSS4.0

CVE-2025-1158 - ESAFENET CDG addPolicyToSafetyGroup.jsp sql injection

A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injection. It is possible to launch the attack remotely. The expl…

πŸ“… Published: Feb. 10, 2025, 9:31 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-1157 - Allims lab.online model_recuperar_senha.php sql injection

A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql injection. The attack may be initiated remotely. The exploit h…

πŸ“… Published: Feb. 10, 2025, 9 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 11:14 p.m.
Total resulsts: 343919
Page 6279 of 34,392
Β« previous page Β» next page
Filters