2.4

CVSS4.0

CVE-2025-2866 - PDF signature forgery with adbe.pkcs7.sha1 SubFilter

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid T…

📅 Published: April 27, 2025, 7:04 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:18 p.m.

5.3

CVSS4.0

CVE-2025-3982 - nortikin Sverchok Set Property Mk2 Node getsetprop_mk2.py SvSetPropNodeMK2 prototype pollution

A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads to improperly controlled modification of obj…

📅 Published: April 27, 2025, 7 p.m. 🔄 Last Modified: May 12, 2025, 7:05 p.m.

5.3

CVSS4.0

CVE-2025-3981 - wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System details improper authorization

A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This issue affects some unknown processing of the file /v1/prescription/details/. The manipulation leads to improper authorization. The attack may be initiated remot…

📅 Published: April 27, 2025, 6:31 p.m. 🔄 Last Modified: May 12, 2025, 7:05 p.m.

5.3

CVSS4.0

CVE-2025-3980 - wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System list improper authorization

A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability affects unknown code of the file /v1/prescription/list. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has bee…

📅 Published: April 27, 2025, 6 p.m. 🔄 Last Modified: May 12, 2025, 7:06 p.m.

5.3

CVSS4.0

CVE-2025-3979 - dazhouda lecms Password Change index.php cross-site request forgery

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Th…

📅 Published: April 27, 2025, 5:31 p.m. 🔄 Last Modified: May 12, 2025, 7:06 p.m.

5.3

CVSS4.0

CVE-2025-3978 - dazhouda lecms user_set.htm information disclosure

A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclose…

📅 Published: April 27, 2025, 5 p.m. 🔄 Last Modified: May 12, 2025, 7:06 p.m.

5.3

CVSS4.0

CVE-2025-3977 - iteachyou Dreamer CMS Attachment download improper authorization

A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/attachment/download of the component Attachment Handler. The manipulation of the argument ID leads to improper authoriza…

📅 Published: April 27, 2025, 4:31 p.m. 🔄 Last Modified: May 12, 2025, 7:07 p.m.

6.9

CVSS4.0

CVE-2025-3976 - PHPGurukul COVID19 Testing Management System new-user-testing.php sql injection

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /new-user-testing.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to launch the attack remotely. T…

📅 Published: April 27, 2025, 4 p.m. 🔄 Last Modified: May 7, 2025, 6:38 p.m.

6.9

CVSS4.0

CVE-2025-3975 - ScriptAndTools eCommerce-website-in-PHP subscriber-csv.php information disclosure

A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disc…

📅 Published: April 27, 2025, 3:31 p.m. 🔄 Last Modified: May 12, 2025, 7:07 p.m.

6.9

CVSS4.0

CVE-2025-3974 - PHPGurukul COVID19 Testing Management System edit-phlebotomist.php sql injection

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-phlebotomist.php?pid=11. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotel…

📅 Published: April 27, 2025, 3 p.m. 🔄 Last Modified: May 7, 2025, 6:40 p.m.
Total resulsts: 346625
Page 5397 of 34,663
« previous page » next page
Filters