4.8

CVSS4.0

CVE-2025-3825 - SourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting

A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument txtcategory_name leads to cross site scripting…

πŸ“… Published: April 20, 2025, 11:31 a.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3824 - SourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting

A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argument txtprice/txtproduct_name leads to cross site scripting. Th…

πŸ“… Published: April 20, 2025, 11 a.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3823 - SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txtexpirydate leads to cross site scripting. It…

πŸ“… Published: April 20, 2025, 10:31 a.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3822 - SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtconfirm_password/txtnew_password/txtold_password leads to cr…

πŸ“… Published: April 20, 2025, 6:31 a.m. πŸ”„ Last Modified: April 24, 2025, 3:40 p.m.

4.8

CVSS4.0

CVE-2025-3821 - SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The …

πŸ“… Published: April 20, 2025, 4 a.m. πŸ”„ Last Modified: April 24, 2025, 3:43 p.m.

2.9

CVSS3.1

CVE-2025-43962 - LibRaw: Out-of-Bounds Read in LibRaw's phase_one_correct Function

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.8

CVSS3.1

CVE-2025-43928 -

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 4 p.m.

2.2

CVSS3.1

CVE-2025-43955 -

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.3

CVSS3.1

CVE-2020-36845 -

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.9

CVSS3.1

CVE-2025-43964 - LibRaw: Improper Validation of Specified Quantity in Input in LibRaw

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.
Total resulsts: 291752
Page 78 of 29,176
Β« previous page Β» next page
Filters