6.9

CVSS4.0

CVE-2025-5401 - chaitak-gorai Blogbook GET Parameter post.php sql injection

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /post.php of the component GET Parameter Handler. The manipulation of the argument p_id leads …

πŸ“… Published: June 1, 2025, 1 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:13 p.m.

6.3

CVSS3.1

CVE-2025-33005 - IBM Planning Analytics Local session fixation

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: June 1, 2025, 11:39 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:53 p.m.

6.5

CVSS3.1

CVE-2025-33004 - IBM Planning Analytics Local path traversal

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

πŸ“… Published: June 1, 2025, 11:37 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:53 p.m.

4.8

CVSS3.1

CVE-2025-2896 - IBM Planning Analytics Local cross-site scripting

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: June 1, 2025, 11:36 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:54 p.m.

5.4

CVSS3.1

CVE-2025-25044 - IBM Planning Analytics Local cross-site scripting

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: June 1, 2025, 11:35 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:55 p.m.

6.5

CVSS3.1

CVE-2025-1499 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

πŸ“… Published: June 1, 2025, 11:30 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:54 p.m.

6.9

CVSS4.0

CVE-2025-5400 - chaitak-gorai Blogbook GET Parameter user.php sql injection

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classified as critical. Affected is an unknown function of the file /user.php of the component GET Parameter Handler. The manipulation of the argument u_id leads to sql injection. It is p…

πŸ“… Published: June 1, 2025, 8:31 a.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:15 p.m.

5.3

CVSS4.0

CVE-2025-5390 - JeeWMS File filedeal.do filedeal access control

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This…

πŸ“… Published: May 31, 2025, 7 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 8:43 p.m.

5.3

CVSS4.0

CVE-2025-5389 - JeeWMS File generateController.do dogenerateOne2Many access control

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation leads to improper access controls. The attack m…

πŸ“… Published: May 31, 2025, 6:31 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 8:43 p.m.

5.3

CVSS4.0

CVE-2025-5388 - JeeWMS generateController.do dogenerate sql injection

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched remotely. This product takes the approach of rollin…

πŸ“… Published: May 31, 2025, 6 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 8:43 p.m.
Total resulsts: 343923
Page 4684 of 34,393
Β« previous page Β» next page
Filters