4.8

CVSS4.0

CVE-2025-2355 - BlackVue App API Endpoint credentials storage

A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component API Endpoint Handler. The manipulation of the argument BCS_TOKEN/SECRET_KEY leads to unprotected storage of credentials. Local access is req…

πŸ“… Published: March 17, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-2354 - VAM Virtual Airlines Manager index.php cross site scripting

A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vam/index.php. The manipulation of the argument registry_id/plane_icao/hub_id leads to cross site scripting. The attack can be …

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-29427 -

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.5

CVSS3.1

CVE-2025-29425 -

Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

9.1

CVSS3.1

CVE-2025-25650 -

An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.2

CVSS3.1

CVE-2025-29431 -

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 12:30 p.m.

4.3

CVSS3.1

CVE-2025-25621 -

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 2:59 p.m.

5

CVSS3.1

CVE-2025-26127 -

A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2025-29426 -

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 12:30 p.m.

6.1

CVSS3.1

CVE-2025-29429 -

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.

πŸ“… Published: March 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.
Total resulsts: 349182
Page 6328 of 34,919
Β« previous page Β» next page
Filters