9.8

CVSS3.1

CVE-2025-40906 - BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vu…

BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serial…

📅 Published: May 16, 2025, 3:15 p.m. 🔄 Last Modified: Sept. 9, 2025, 1:54 p.m.

6.9

CVSS4.0

CVE-2025-4785 - PHPGurukul Daily Expense Tracker System user-profile.php sql injection

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user-profile.php. The manipulation of the argument fullname/contactnumber leads to sql injection. The attack may be launched rem…

📅 Published: May 16, 2025, 3 p.m. 🔄 Last Modified: May 21, 2025, 9 p.m.

2.6

CVSS3.1

CVE-2025-47794 - Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permiss…

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud runni…

📅 Published: May 16, 2025, 2:35 p.m. 🔄 Last Modified: Sept. 30, 2025, 7:37 p.m.

4.3

CVSS3.1

CVE-2025-47793 - Nextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attach…

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfo…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: Sept. 8, 2025, 9:54 p.m.

5.3

CVSS4.0

CVE-2025-4782 - SourceCodester/oretnom23 Stock Management System view_receiving sql injection

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initia…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: May 23, 2025, 1:04 p.m.

5.3

CVSS4.0

CVE-2025-4781 - PHPGurukul Park Ticketing Management System forgot-password.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an unknown function of the file /forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. It is possible to launch the attack remotely. The expl…

📅 Published: May 16, 2025, 2:31 p.m. 🔄 Last Modified: May 21, 2025, 8:59 p.m.

5

CVSS3.1

CVE-2025-47792 - Nextcloud Desktop 3rdparty applications can create share links via socket API

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextc…

📅 Published: May 16, 2025, 2:13 p.m. 🔄 Last Modified: Sept. 8, 2025, 9:22 p.m.

4.3

CVSS3.1

CVE-2025-47791 - Nextcloud Server's test remote endpoint is not rate limited

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests t…

📅 Published: May 16, 2025, 2:09 p.m. 🔄 Last Modified: Sept. 19, 2025, 5:41 p.m.

6.4

CVSS3.1

CVE-2025-47790 - Nextcloud Server doesn't request second factor after session timeout

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirma…

📅 Published: May 16, 2025, 2:02 p.m. 🔄 Last Modified: Sept. 30, 2025, 7:59 p.m.

5.3

CVSS4.0

CVE-2025-4780 - PHPGurukul Park Ticketing Management System foreigner-search.php sql injection

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The ex…

📅 Published: May 16, 2025, 2 p.m. 🔄 Last Modified: June 5, 2025, 7:36 p.m.
Total resulsts: 343923
Page 4844 of 34,393
« previous page » next page
Filters