2.3

CVSS4.0

CVE-2025-14953 - Open5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereference

A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high le…

πŸ“… Published: Dec. 19, 2025, 4:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

9.3

CVSS4.0

CVE-2025-34433 - AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt

AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, and a derived hash identifier is accessible through unauthent…

πŸ“… Published: Dec. 19, 2025, 3:37 p.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:12 p.m.

1.3

CVSS4.0

CVE-2025-53922 - Galette has access control bypass

Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may bypass intended restrictions on Contributions and Transactions. Version 1.2.0 fixes the issue.

πŸ“… Published: Dec. 19, 2025, 3:10 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 2:55 p.m.

6.9

CVSS4.0

CVE-2025-14952 - Campcodes Supplier Management System add_category.php sql injection

A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now p…

πŸ“… Published: Dec. 19, 2025, 2:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

6.9

CVSS4.0

CVE-2025-14951 - code-projects Scholars Tracking System home.php sql injection

A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /home.php. Such manipulation of the argument post_content leads to sql injection. The attack can be executed remotely. The exploit has been disclosed pub…

πŸ“… Published: Dec. 19, 2025, 2:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:56 a.m.

6.9

CVSS4.0

CVE-2025-14950 - code-projects Scholars Tracking System delete_post.php sql injection

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to th…

πŸ“… Published: Dec. 19, 2025, 1:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

3.8

CVSS4.0

CVE-2025-14881 - Insecure direct object reference

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

πŸ“… Published: Dec. 19, 2025, 12:24 p.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:13 p.m.

3.8

CVSS4.0

CVE-2025-14882 - Insecure direct object reference

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

πŸ“… Published: Dec. 19, 2025, 12:24 p.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:12 p.m.

9.1

CVSS3.1

CVE-2025-1928 - Improper Authentication in Restajet's Online Food Delivery System

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation.This issue affects Online Food Delivery System: through 19122025.Β NOTE: The vendor was contacted early about this discl…

πŸ“… Published: Dec. 19, 2025, 12:08 p.m. πŸ”„ Last Modified: March 26, 2026, 7:33 a.m.

7.1

CVSS3.1

CVE-2025-1927 - CSRF in Restajet's Online Food Delivery System

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery.This issue affects Online Food Delivery System: through 19122025.Β NOTE: The vendor was contacted early about this disclosure but did not respond in…

πŸ“… Published: Dec. 19, 2025, 12:01 p.m. πŸ”„ Last Modified: March 26, 2026, 7:32 a.m.
Total resulsts: 344142
Page 1993 of 34,415
Β« previous page Β» next page
Filters