5.3

CVSS4.0

CVE-2025-0540 - itsourcecode Tailoring Management System expadd.php sql injection

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be initiated remotely. The exploit has been discโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 9 p.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 2:58 p.m.

1.8

CVSS4.0

CVE-2025-23206 - IAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdk

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. โ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:34 p.m. ๐Ÿ”„ Last Modified: Jan. 23, 2026, 3:16 p.m.

5.3

CVSS4.0

CVE-2025-0538 - code-projects Tourism Management System manage-pages.php cross site scripting

A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotelโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:31 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-23205 - `frame-ancestors: self` grants all users access to formgrader in nbgrader

nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomaiโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-23202 - Improper Input Validation in Bible Module for ROBLOX

Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse` and `FetchPassage` functions in the Bible Module are susceptible to injection attacks due to the absence of input validation. This vulnerability could allow an attacker to manipโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:18 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS3.1

CVE-2025-23039 - Cross Site Scripting on URL decode Tooltip in Caido

Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due to improper sanitization in the URL decoding tooltip of HTTP request and response editors. This issue could allow an attacker to execute arbitrary scripts, potentially leading toโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-21606 - Local Privilege Escalation via Exposed XPC Method Due to Client Verification Failure in stats

stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation due to the insecure implementation of its XPC service. The application registers a Mach service under the name `eu.exelban.Stats.SMC.Helper`. The associated binary, eu.exelban.Stโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS4.0

CVE-2024-13026 - Inadequate Encryption Strength Vulnerability in Roche Algo Edge

A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navifyยฎ Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft vโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-0537 - code-projects Car Rental Management System manage-pages.php cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cross site scripting. The attack may be initiatโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 8 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2025-0536 - 1000 Projects Attendance Tracking Management System edit_action.php sql injection

A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The eโ€ฆ

๐Ÿ“… Published: Jan. 17, 2025, 7:31 p.m. ๐Ÿ”„ Last Modified: Feb. 25, 2025, 10:25 p.m.
Total resulsts: 346620
Page 6801 of 34,662
ยซ previous page ยป next page
Filters