6.9

CVSS4.0

CVE-2025-14950 - code-projects Scholars Tracking System delete_post.php sql injection

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to th…

πŸ“… Published: Dec. 19, 2025, 1:32 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

3.8

CVSS4.0

CVE-2025-14881 - Insecure direct object reference

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

πŸ“… Published: Dec. 19, 2025, 12:24 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

3.8

CVSS4.0

CVE-2025-14882 - Insecure direct object reference

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

πŸ“… Published: Dec. 19, 2025, 12:24 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

9.1

CVSS3.1

CVE-2025-1928 - Improper Authentication in Restajet's Online Food Delivery System

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 12:08 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

7.1

CVSS3.1

CVE-2025-1927 - CSRF in Restajet's Online Food Delivery System

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 12:01 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

5.4

CVSS3.1

CVE-2025-1885 - Open Redirect in Restajet's Online Food Delivery System

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 11:47 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 11:47 a.m.

8.7

CVSS4.0

CVE-2025-14847 - Zlib compressed protocol header length confusion may allow memory read

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, Mo…

πŸ“… Published: Dec. 19, 2025, 11 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 11 a.m.

5.4

CVSS3.1

CVE-2025-14455 - Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor…

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for …

πŸ“… Published: Dec. 19, 2025, 9:29 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:29 a.m.

4.3

CVSS3.1

CVE-2025-12361 - myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 -…

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This mak…

πŸ“… Published: Dec. 19, 2025, 9:29 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:29 a.m.

7.5

CVSS4.0

CVE-2025-66524 - Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without fil…

πŸ“… Published: Dec. 19, 2025, 9:24 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.
Total resulsts: 323517
Page 8 of 32,352
Β« previous page Β» next page
Filters