7.5

CVSS3.1

CVE-2025-49125 - Apache Tomcat: Security constraint bypass for pre/post-resources

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.Β  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the…

πŸ“… Published: June 16, 2025, 2:18 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

8.6

CVSS4.0

CVE-2025-3594 -

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and …

πŸ“… Published: June 16, 2025, 2:13 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2025-48988 - Apache Tomcat: FileUpload large number of parts with headers DoS

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be …

πŸ“… Published: June 16, 2025, 2:13 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

4.8

CVSS4.0

CVE-2025-6125 - PHPGurukul Rail Pass Management System aboutus.php cross site scripting

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is possible to launch the attack remotely. The e…

πŸ“… Published: June 16, 2025, 2 p.m. πŸ”„ Last Modified: June 24, 2025, 3:55 p.m.

7.8

CVSS3.1

CVE-2025-36632 - Local Privilege Escalation

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.

πŸ“… Published: June 16, 2025, 1:56 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 8:19 p.m.

8.7

CVSS4.0

CVE-2025-3602 -

Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on t…

πŸ“… Published: June 16, 2025, 1:50 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 5:03 p.m.

6.9

CVSS4.0

CVE-2025-6124 - code-projects Restaurant Order System tablelow.php sql injection

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed t…

πŸ“… Published: June 16, 2025, 1:31 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 7:37 p.m.

6.9

CVSS4.0

CVE-2025-6123 - code-projects Restaurant Order System payment.php sql injection

A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been dis…

πŸ“… Published: June 16, 2025, 1 p.m. πŸ”„ Last Modified: July 7, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2025-6122 - code-projects Restaurant Order System table.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: June 16, 2025, 12:31 p.m. πŸ”„ Last Modified: June 24, 2025, 8:14 p.m.

9.3

CVSS4.0

CVE-2025-6121 - D-Link DIR-632 HTTP POST Request get_pure_content stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is the function get_pure_content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be l…

πŸ“… Published: June 16, 2025, noon πŸ”„ Last Modified: June 17, 2025, 7:37 p.m.
Total resulsts: 346624
Page 4766 of 34,663
Β« previous page Β» next page
Filters