5.4

CVSS3.1

CVE-2024-8186 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

πŸ“… Published: March 3, 2025, 10:02 a.m. πŸ”„ Last Modified: March 3, 2025, 12:32 p.m.

6.9

CVSS4.0

CVE-2025-1859 - PHPGurukul News Portal login.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: March 3, 2025, 9 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-24654 - WordPress Squirrly SEO plugin <= 12.4.07 - Broken Access Control vulnerability

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.

πŸ“… Published: March 3, 2025, 8:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

10

CVSS4.0

CVE-2025-1867 - HTTP Response Smuggling Vulnerability in libhv

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through 1.3.3.

πŸ“… Published: March 3, 2025, 8:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-1866 - Undefined Behavior Due to Out-of-Bounds Pointer Arithmetic in libwebsockets

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This issue affects libwebsockets before 4.3.4 and is present in code built specifically for the Win32 platf…

πŸ“… Published: March 3, 2025, 8:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1858 - Codezips Online Shopping Website success.php sql injection

A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public …

πŸ“… Published: March 3, 2025, 8:31 a.m. πŸ”„ Last Modified: June 24, 2025, 2:37 p.m.

5.3

CVSS3.1

CVE-2025-25280 -

Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may reboot the device by sending a specially crafted request.

πŸ“… Published: March 3, 2025, 8:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-24846 -

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.

πŸ“… Published: March 3, 2025, 8:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-1864 - Buffer Overflow and Potential Code Execution in Radare2

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.

πŸ“… Published: March 3, 2025, 8:15 a.m. πŸ”„ Last Modified: July 1, 2025, 2:55 p.m.

6.9

CVSS4.0

CVE-2025-1857 - PHPGurukul Nipah Virus Testing Management System check_availability.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. It is possible to initiate the attack remotely. The ex…

πŸ“… Published: March 3, 2025, 8 a.m. πŸ”„ Last Modified: June 24, 2025, 3:52 p.m.
Total resulsts: 349182
Page 6497 of 34,919
Β« previous page Β» next page
Filters