0.0

CVE-2025-25228 - Extension - virtuemart.net - SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

๐Ÿ“… Published: April 21, 2025, 7:16 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 4:35 a.m.

9.2

CVSS4.0

CVE-2025-0632 - Local File Inclusion (LFI) leading to sensitive data exposure

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution.ย A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfโ€ฆ

๐Ÿ“… Published: April 21, 2025, 5:27 a.m. ๐Ÿ”„ Last Modified: April 28, 2025, 3:15 a.m.

6.8

CVSS3.1

CVE-2025-43972 -

An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.3

CVSS3.1

CVE-2025-43970 -

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.8

CVSS3.1

CVE-2025-43973 -

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.5

CVSS3.1

CVE-2025-32408 -

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 4:06 p.m.

6.1

CVSS3.1

CVE-2025-28121 -

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 4:41 p.m.

3.4

CVSS3.1

CVE-2025-43916 -

Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC 6819 section 5.2.3.5. An authorization code may be sent to an attacker-controlled destination. This might have fโ€ฆ

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

8.6

CVSS3.1

CVE-2025-43971 -

An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

9.8

CVSS3.1

CVE-2025-29287 -

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 4:37 p.m.
Total resulsts: 291831
Page 83 of 29,184
ยซ previous page ยป next page
Filters