6.9

CVSS4.0

CVE-2025-1952 - PHPGurukul Restaurant Table Booking System password-recovery.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. The manipulation of the argument username/mobileno leads to sql injection. It is possible to launch the attack re…

πŸ“… Published: March 4, 2025, 7 p.m. πŸ”„ Last Modified: April 3, 2025, 1:31 p.m.

5.3

CVSS4.0

CVE-2025-1949 - ZZCMS URL register_nodb.php cross site scripting

A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The att…

πŸ“… Published: March 4, 2025, 7 p.m. πŸ”„ Last Modified: April 23, 2025, 3 p.m.

5.3

CVSS4.0

CVE-2025-1969 - Request approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process

πŸ“… Published: March 4, 2025, 6:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1947 - hzmanyun Education and Training System UploadImageController.java scorm command injection

A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: March 4, 2025, 6:31 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 7:54 p.m.

5.3

CVSS4.0

CVE-2025-1946 - hzmanyun Education and Training System exportPDF command injection

A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF. The manipulation of the argument id leads to command injection. The attack may be launched remotely. The exploit has …

πŸ“… Published: March 4, 2025, 6:31 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 8:24 p.m.

5.3

CVSS3.0

CVE-2020-3122 - Cisco Content Security Management Appliance Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.

πŸ“… Published: March 4, 2025, 6:22 p.m. πŸ”„ Last Modified: July 31, 2025, 7:44 p.m.

7.5

CVSS3.0

CVE-2019-1815 - Cisco Meraki MX67 and MX68 Sensitive Information Disclosure Vulnerability

A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper a…

πŸ“… Published: March 4, 2025, 6:14 p.m. πŸ”„ Last Modified: July 12, 2025, 11:06 p.m.

7.1

CVSS4.0

CVE-2024-10930 - Carrier Block Load Privilege Escalation

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

πŸ“… Published: March 4, 2025, 5:21 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 6:42 p.m.

7.7

CVSS3.1

CVE-2024-41147 -

An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: March 4, 2025, 5:21 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:14 p.m.

4.6

CVSS3.1

CVE-2025-27402 - Tuleap is missing CSRF protections on tracker fields administrative operations

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is …

πŸ“… Published: March 4, 2025, 5 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 3:37 p.m.
Total resulsts: 349182
Page 6457 of 34,919
Β« previous page Β» next page
Filters