5.3
CVE-2025-0540 - itsourcecode Tailoring Management System expadd.php sql injection
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be initiated remotely. The exploit has been discโฆ
1.8
CVE-2025-23206 - IAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdk
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. โฆ
5.3
CVE-2025-0538 - code-projects Tourism Management System manage-pages.php cross site scripting
A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotelโฆ
6.9
CVE-2025-23205 - `frame-ancestors: self` grants all users access to formgrader in nbgrader
nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomaiโฆ
10
CVE-2025-23202 - Improper Input Validation in Bible Module for ROBLOX
Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse` and `FetchPassage` functions in the Bible Module are susceptible to injection attacks due to the absence of input validation. This vulnerability could allow an attacker to manipโฆ
5.2
CVE-2025-23039 - Cross Site Scripting on URL decode Tooltip in Caido
Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due to improper sanitization in the URL decoding tooltip of HTTP request and response editors. This issue could allow an attacker to execute arbitrary scripts, potentially leading toโฆ
8.7
CVE-2025-21606 - Local Privilege Escalation via Exposed XPC Method Due to Client Verification Failure in stats
stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation due to the insecure implementation of its XPC service. The application registers a Mach service under the name `eu.exelban.Stats.SMC.Helper`. The associated binary, eu.exelban.Stโฆ
6.1
CVE-2024-13026 - Inadequate Encryption Strength Vulnerability in Roche Algo Edge
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navifyยฎ Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft vโฆ
5.1
CVE-2025-0537 - code-projects Car Rental Management System manage-pages.php cross site scripting
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cross site scripting. The attack may be initiatโฆ
5.3
CVE-2025-0536 - 1000 Projects Attendance Tracking Management System edit_action.php sql injection
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The eโฆ