5.3

CVSS4.0

CVE-2025-8347 - Kehua Charging Pile Cloud Platform findAllTask sql injection

A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an unknown part of the file /sys/task/findAllTask. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the publ…

πŸ“… Published: July 31, 2025, 3:02 a.m. πŸ”„ Last Modified: July 31, 2025, 3:15 a.m.

5.3

CVSS4.0

CVE-2025-8346 - Portabilis i-Educar educar_aluno_lst.php cross site scripting

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file /educar_aluno_lst.php. The manipulation of the argument ref_cod_matricula with the input "><img%20src=x%20onerror=alert(%27CVE-Hunters%2…

πŸ“… Published: July 31, 2025, 2:32 a.m. πŸ”„ Last Modified: July 31, 2025, 3:15 a.m.

5.3

CVSS4.0

CVE-2025-8345 - Shanghai Lingdang Information Technology Lingdang CRM yunzhijiaApi.php delete_user sql injection

A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this vulnerability is the function delete_user of the file crm/WeiXinApp/yunzhijia/yunzhijiaApi.php. The manipulation of the argument function leads to sql injection.…

πŸ“… Published: July 31, 2025, 2:02 a.m. πŸ”„ Last Modified: July 31, 2025, 3:15 a.m.

5.3

CVSS4.0

CVE-2025-8344 - openviglet shio ShStaticFileAPI.java shStaticFileUpload unrestricted upload

A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is pos…

πŸ“… Published: July 31, 2025, 1:32 a.m. πŸ”„ Last Modified: July 31, 2025, 2:15 a.m.

5.3

CVSS4.0

CVE-2025-8343 - openviglet shio ShStaticFileAPI.java shStaticFilePreUpload path traversal

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. T…

πŸ“… Published: July 31, 2025, 1:02 a.m. πŸ”„ Last Modified: July 31, 2025, 1:15 a.m.

5.3

CVSS4.0

CVE-2025-8340 - code-projects Intern Membership Management System Error Message fill_details.php cross site scripti…

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file fill_details.php of the component Error Message Handler. The manipulation of the argument email leads to cross site scripting.…

πŸ“… Published: July 31, 2025, 12:32 a.m. πŸ”„ Last Modified: July 31, 2025, 1:15 a.m.

6.9

CVSS4.0

CVE-2025-8339 - code-projects Intern Membership Management System student_login.php sql injection

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /student_login.php. The manipulation of the argument user_name/password leads to sql injection. It is possible to initiate the attack remo…

πŸ“… Published: July 31, 2025, 12:02 a.m. πŸ”„ Last Modified: July 31, 2025, 1:15 a.m.

6.5

CVSS3.1

CVE-2025-36040 - IBM Aspera Faspex session fixation

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

πŸ“… Published: July 30, 2025, 11:48 p.m. πŸ”„ Last Modified: July 31, 2025, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-36039 - IBM Aspera Faspex bypass security

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,

πŸ“… Published: July 30, 2025, 11:47 p.m. πŸ”„ Last Modified: July 31, 2025, 12:15 a.m.

5.1

CVSS4.0

CVE-2025-49082 - Permissions bypass vulnerability in the Secure Access administrative console of Absolute Secure Acc…

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack comple…

πŸ“… Published: July 30, 2025, 11:45 p.m. πŸ”„ Last Modified: July 31, 2025, 12:15 a.m.
Total resulsts: 303770
Page 1 of 30,377
Β» next page
Filters