5.3

CVSS3.1

CVE-2024-47262 -

Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affect…

πŸ“… Published: March 4, 2025, 5:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-47260 -

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory.Β  Axis has released patched AXIS OS versions for the high…

πŸ“… Published: March 4, 2025, 5:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-47259 -

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device with the purpose to exhaust system resources. Axi…

πŸ“… Published: March 4, 2025, 5:15 a.m. πŸ”„ Last Modified: Jan. 22, 2026, 4:35 p.m.

5.1

CVSS4.0

CVE-2025-1906 - PHPGurukul Restaurant Table Booking System profile.php sql injection

A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploi…

πŸ“… Published: March 4, 2025, 5 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.1

CVSS4.0

CVE-2025-1905 - SourceCodester Employee Management System employee.php cross site scripting

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The expl…

πŸ“… Published: March 4, 2025, 4:31 a.m. πŸ”„ Last Modified: March 6, 2025, 12:17 p.m.

5.1

CVSS4.0

CVE-2025-1904 - code-projects Blood Bank System A+.php cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /Blood/A+.php. The manipulation of the argument Availibility leads to cross site scripting. The attack may be launched remote…

πŸ“… Published: March 4, 2025, 4:31 a.m. πŸ”„ Last Modified: March 6, 2025, 12:17 p.m.

9.8

CVSS3.1

CVE-2025-1307 - Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and a…

πŸ“… Published: March 4, 2025, 4:26 a.m. πŸ”„ Last Modified: April 22, 2026, 2:15 a.m.

8.8

CVSS3.1

CVE-2025-1306 - Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload a…

πŸ“… Published: March 4, 2025, 4:26 a.m. πŸ”„ Last Modified: April 22, 2026, 6 p.m.

6.9

CVSS4.0

CVE-2025-1903 - Codezips Online Shopping Website cart_add.php sql injection

A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…

πŸ“… Published: March 4, 2025, 4 a.m. πŸ”„ Last Modified: March 6, 2025, 12:21 p.m.

6.9

CVSS4.0

CVE-2025-1902 - PHPGurukul Student Record System password-recovery.php sql injection

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has bee…

πŸ“… Published: March 4, 2025, 4 a.m. πŸ”„ Last Modified: March 6, 2025, 12:21 p.m.
Total resulsts: 349182
Page 6463 of 34,919
Β« previous page Β» next page
Filters