5.3

CVSS4.0

CVE-2025-1202 - SourceCodester Best Church Management Software edit_slider.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best Church Management Software 1.1. Affected is an unknown function of the file /admin/edit_slider.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: Feb. 12, 2025, 2:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:02 p.m.

5.3

CVSS4.0

CVE-2025-1201 - SourceCodester Best Church Management Software profile_crud.php sql injection

A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/app/profile_crud.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Feb. 12, 2025, 2 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:01 p.m.

3.9

CVSS3.1

CVE-2024-23563 - HCL Connections Docs is vulnerable to a sensitive information disclosure

HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

πŸ“… Published: Feb. 12, 2025, 1:47 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:25 p.m.

5.3

CVSS4.0

CVE-2025-1200 - SourceCodester Best Church Management Software slider_crud.php sql injection

A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/app/slider_crud.php. The manipulation of the argument del_id leads to sql injection. The attack can be initiated remotely. Th…

πŸ“… Published: Feb. 12, 2025, 1:31 p.m. πŸ”„ Last Modified: April 29, 2025, 8:24 p.m.

8.8

CVSS3.1

CVE-2025-26378 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: April 10, 2025, 8:25 p.m.

8.1

CVSS3.1

CVE-2025-26377 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-26376 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: April 10, 2025, 7:54 p.m.

8.8

CVSS3.1

CVE-2025-26375 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrary privileges via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: April 10, 2025, 6:55 p.m.

6.5

CVSS3.1

CVE-2025-26374 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26373 -

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.

πŸ“… Published: Feb. 12, 2025, 1:30 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 3:41 p.m.
Total resulsts: 349182
Page 6761 of 34,919
Β« previous page Β» next page
Filters