6.9

CVSS4.0

CVE-2025-4924 - SourceCodester Client Database Management System user_void_transaction.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotel…

πŸ“… Published: May 19, 2025, 8:31 a.m. πŸ”„ Last Modified: May 21, 2025, 5:41 p.m.

5.1

CVSS4.0

CVE-2025-27566 -

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authentica…

πŸ“… Published: May 19, 2025, 8:09 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 7:22 p.m.

4.8

CVSS4.0

CVE-2025-32999 -

Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary scri…

πŸ“… Published: May 19, 2025, 8:08 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 7:20 p.m.

9.2

CVSS4.0

CVE-2025-36560 -

Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.

πŸ“… Published: May 19, 2025, 8:08 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 7:14 p.m.

2.1

CVSS4.0

CVE-2025-41429 -

a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.

πŸ“… Published: May 19, 2025, 8:07 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 7:05 p.m.

6.9

CVSS4.0

CVE-2025-4923 - SourceCodester Client Database Management System user_delivery_update.php unrestricted upload

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The att…

πŸ“… Published: May 19, 2025, 8 a.m. πŸ”„ Last Modified: May 28, 2025, 12:50 p.m.

8.4

CVSS4.0

CVE-2025-47760 -

V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

πŸ“… Published: May 19, 2025, 7:48 a.m. πŸ”„ Last Modified: May 19, 2025, 5:33 p.m.

8.4

CVSS4.0

CVE-2025-47759 -

V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

πŸ“… Published: May 19, 2025, 7:47 a.m. πŸ”„ Last Modified: May 19, 2025, 5:33 p.m.

8.4

CVSS4.0

CVE-2025-47758 -

V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

πŸ“… Published: May 19, 2025, 7:47 a.m. πŸ”„ Last Modified: May 19, 2025, 5:33 p.m.

8.4

CVSS4.0

CVE-2025-47757 -

V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

πŸ“… Published: May 19, 2025, 7:47 a.m. πŸ”„ Last Modified: May 19, 2025, 5:33 p.m.
Total resulsts: 342256
Page 4652 of 34,226
Β« previous page Β» next page
Filters