6.9

CVSS4.0

CVE-2025-2386 - PHPGurukul Local Services Search Engine Management System serviceman-search.php sql injection

A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotel…

📅 Published: March 17, 2025, 5 p.m. 🔄 Last Modified: March 17, 2025, 7:15 p.m.

7.8

CVSS3.1

CVE-2024-48830 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Co…

📅 Published: March 17, 2025, 4:56 p.m. 🔄 Last Modified: March 18, 2025, 3:55 a.m.

8.8

CVSS3.1

CVE-2024-48013 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

📅 Published: March 17, 2025, 4:45 p.m. 🔄 Last Modified: March 18, 2025, 3:55 a.m.

6.9

CVSS4.0

CVE-2025-2385 - code-projects Modern Bag login.php sql injection

A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument userEmail/userPassword leads to sql injection. The attack can be initiated remotely. The exploit has been discl…

📅 Published: March 17, 2025, 4:31 p.m. 🔄 Last Modified: March 17, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2025-2384 - code-projects Real Estate Property Management System Parameter InsertCustomer.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txtName/txtAddress/cmbCity/txtEmail/cmbGender/t…

📅 Published: March 17, 2025, 4 p.m. 🔄 Last Modified: March 17, 2025, 6:15 p.m.

8.2

CVSS3.1

CVE-2025-2241 - Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract s…

📅 Published: March 17, 2025, 3:52 p.m. 🔄 Last Modified: March 17, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-2383 - PHPGurukul Doctor Appointment Management System search.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launch…

📅 Published: March 17, 2025, 3:31 p.m. 🔄 Last Modified: March 17, 2025, 7:15 p.m.

6.3

CVSS4.0

CVE-2025-1774 - Logs manipulation in BotSense

Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue …

📅 Published: March 17, 2025, 3:05 p.m. 🔄 Last Modified: March 17, 2025, 3:17 p.m.

6.9

CVSS4.0

CVE-2025-2382 - PHPGurukul Online Banquet Booking System booking-search.php sql injection

A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely…

📅 Published: March 17, 2025, 3 p.m. 🔄 Last Modified: March 17, 2025, 3:49 p.m.

2.1

CVSS4.0

CVE-2025-27512 - Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods

Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot the system into the d…

📅 Published: March 17, 2025, 2:46 p.m. 🔄 Last Modified: March 17, 2025, 3:15 p.m.
Total resulsts: 285611
Page 7 of 28,562
« previous page » next page
Filters