5.1

CVSS4.0

CVE-2025-5059 - Campcodes Online Shopping Portal edit-subcategory.php unrestricted upload

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. It is possible to initiate thโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 2:02 a.m.

8.6

CVSS4.0

CVE-2025-34025 - Versa Concerto Insecure Docker Mount Container Escape

The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host โ€ฆ

๐Ÿ“… Published: May 21, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-48070 - Plane has insecure permissions in UserSerializer

Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scriptiโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 9:44 a.m.

7.5

CVSS3.1

CVE-2025-47947 - ModSecurity Has Possible DoS Vulnerability

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there iโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10:08 p.m. ๐Ÿ”„ Last Modified: June 20, 2025, 4:13 p.m.

9.2

CVSS4.0

CVE-2025-34026 - Versa Concerto Actuator Authentication Bypass Information Leak

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is knownโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Jan. 23, 2026, 6:39 p.m.

6.9

CVSS4.0

CVE-2025-5057 - Campcodes Online Shopping Portal insert-product.php sql injection

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 2:04 a.m.

6.9

CVSS4.0

CVE-2025-5056 - Campcodes Online Shopping Portal edit-products.php sql injection

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-products.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotelyโ€ฆ

๐Ÿ“… Published: May 21, 2025, 10 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 2:08 a.m.

10

CVSS4.0

CVE-2025-34027 - Versa Concerto Authentication Bypass File Write Remote Code Execution

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combinationโ€ฆ

๐Ÿ“… Published: May 21, 2025, 9:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-47942 - Learners on edX Platform can download python_lib.zip

The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the python_lib.zip asset from courses, which is a concern since it often contains custom grading code or answers to course problemโ€ฆ

๐Ÿ“… Published: May 21, 2025, 9:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5053 - FreeFloat FTP Server MDIR Command buffer overflow

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed tโ€ฆ

๐Ÿ“… Published: May 21, 2025, 9 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 7:34 p.m.
Total resulsts: 345142
Page 4891 of 34,515
ยซ previous page ยป next page
Filters