9.8

CVSS3.1

CVE-2025-44831 -

EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 6:26 p.m.

7.2

CVSS3.1

CVE-2025-28057 -

owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 2:09 a.m.

6.5

CVSS3.1

CVE-2025-45746 -

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and beca…

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-45861 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 15, 2025, 6:37 p.m.

7.5

CVSS3.1

CVE-2025-28055 -

upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 1:58 a.m.

6.1

CVSS3.1

CVE-2025-47204 -

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exp…

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 2:02 a.m.

9.8

CVSS3.1

CVE-2023-49641 - Billing Software v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

πŸ“… Published: May 12, 2025, 11:34 p.m. πŸ”„ Last Modified: May 13, 2025, 7:35 p.m.

1.3

CVSS4.0

CVE-2025-46825 - Kanboard has stored Cross-site Scripting vulnerability in project name

Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XSS) Vulnerability in the `name` parameter of the `http://localhost/?controller=ProjectCreationController&action=create` form. This vulnerability allows…

πŸ“… Published: May 12, 2025, 10:53 p.m. πŸ”„ Last Modified: July 11, 2025, 2:41 p.m.

5.5

CVSS3.1

CVE-2025-31220 -

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to read sensitive location information.

πŸ“… Published: May 12, 2025, 9:43 p.m. πŸ”„ Last Modified: April 2, 2026, 7:19 p.m.

7.8

CVSS3.1

CVE-2025-24258 -

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain root privileges.

πŸ“… Published: May 12, 2025, 9:43 p.m. πŸ”„ Last Modified: April 2, 2026, 7:19 p.m.
Total resulsts: 342768
Page 4810 of 34,277
Β« previous page Β» next page
Filters