4.8

CVSS4.0

CVE-2025-3823 - SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txtexpirydate leads to cross site scripting. It…

πŸ“… Published: April 20, 2025, 10:31 a.m. πŸ”„ Last Modified: April 30, 2025, 5:38 p.m.

4.8

CVSS4.0

CVE-2025-3822 - SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtconfirm_password/txtnew_password/txtold_password leads to cr…

πŸ“… Published: April 20, 2025, 6:31 a.m. πŸ”„ Last Modified: April 24, 2025, 3:40 p.m.

4.8

CVSS4.0

CVE-2025-3821 - SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The …

πŸ“… Published: April 20, 2025, 4 a.m. πŸ”„ Last Modified: April 24, 2025, 3:43 p.m.

5.8

CVSS3.1

CVE-2025-43928 -

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 4 p.m.

2.9

CVSS3.1

CVE-2025-43967 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 4:05 p.m.

4.9

CVSS3.1

CVE-2025-43954 -

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 4:49 p.m.

2.2

CVSS3.1

CVE-2025-43955 -

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 2:26 p.m.

2.9

CVSS3.1

CVE-2025-43966 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 4:03 p.m.

2.9

CVSS3.1

CVE-2025-43963 - LibRaw: out-of-buffer access

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

4.1

CVSS3.1

CVE-2025-43929 -

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

πŸ“… Published: April 20, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 3:46 p.m.
Total resulsts: 343968
Page 5190 of 34,397
Β« previous page Β» next page
Filters