6.9

CVSS4.0

CVE-2025-5361 - Campcodes Online Hospital Management System contact.php sql injection

A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The expl…

πŸ“… Published: May 30, 2025, 8 p.m. πŸ”„ Last Modified: June 3, 2025, 3:35 p.m.

8.7

CVSS4.0

CVE-2025-48882 - PHPOffice Math allows XXE when processing an XML file in the MathML format

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability.

πŸ“… Published: May 30, 2025, 7:43 p.m. πŸ”„ Last Modified: June 2, 2025, 5:32 p.m.

8.9

CVSS4.0

CVE-2025-48949 - Navidrome allows SQL Injection via role parameter

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the `role` parameter within the API endpoint `/api/artist`. Attackers can exploit this flaw to inject arbitrary SQL queries, potentiall…

πŸ“… Published: May 30, 2025, 7:40 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:12 p.m.

6.9

CVSS4.0

CVE-2025-5360 - Campcodes Online Hospital Management System book-appointment.php sql injection

A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can be initiated remotely. The exploit has been …

πŸ“… Published: May 30, 2025, 7:31 p.m. πŸ”„ Last Modified: June 3, 2025, 3:35 p.m.

7.4

CVSS4.0

CVE-2025-48948 - Navidrome Transcoding Permission Bypass Vulnerability Report

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user to bypass authorization checks and perform administrator-only transcoding configuration operations, including creating, modify…

πŸ“… Published: May 30, 2025, 7:25 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:17 p.m.

3.7

CVSS3.1

CVE-2025-48946 - liboqs affected by theoretical design flaw in HQC

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malformed ciphertexts sharing the same implicit …

πŸ“… Published: May 30, 2025, 7:21 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:06 p.m.

6.9

CVSS4.0

CVE-2025-2503 -

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.

πŸ“… Published: May 30, 2025, 7:14 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 3:31 p.m.

8.5

CVSS4.0

CVE-2025-2502 -

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

πŸ“… Published: May 30, 2025, 7:14 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

8.5

CVSS4.0

CVE-2025-2501 -

An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

πŸ“… Published: May 30, 2025, 7:14 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

4.8

CVSS4.0

CVE-2025-1479 -

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.

πŸ“… Published: May 30, 2025, 7:13 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.
Total resulsts: 343926
Page 4689 of 34,393
Β« previous page Β» next page
Filters