6.9

CVSS4.0

CVE-2025-3180 - projectworlds Online Doctor Appointment Booking System deleteschedule.php sql injection

A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched r…

πŸ“… Published: April 3, 2025, 9 p.m. πŸ”„ Last Modified: April 8, 2025, 6:09 p.m.

6.9

CVSS4.0

CVE-2025-3179 - projectworlds Online Doctor Appointment Booking System deletepatient.php sql injection

A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The e…

πŸ“… Published: April 3, 2025, 9 p.m. πŸ”„ Last Modified: April 8, 2025, 6:38 p.m.

6.9

CVSS4.0

CVE-2025-3178 - projectworlds Online Doctor Appointment Booking System deleteappointment.php sql injection

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remot…

πŸ“… Published: April 3, 2025, 8:31 p.m. πŸ”„ Last Modified: April 8, 2025, 6:48 p.m.

2.3

CVSS4.0

CVE-2025-3177 - FastCMS JWT hard-coded key

A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The …

πŸ“… Published: April 3, 2025, 8 p.m. πŸ”„ Last Modified: April 8, 2025, 7:40 p.m.

8.7

CVSS4.0

CVE-2025-31489 - MinIO performs incomplete signature validation for unsigned-trailer uploads

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on t…

πŸ“… Published: April 3, 2025, 7:36 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-31485 - GraphQL grant on a property might be cached with different objects

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() method is meant to prevent the caching but the paren…

πŸ“… Published: April 3, 2025, 7:31 p.m. πŸ”„ Last Modified: July 13, 2025, 11:06 a.m.

6.9

CVSS4.0

CVE-2025-3176 - Project Worlds Online Lawyer Management System single_lawyer.php sql injection

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: April 3, 2025, 7:31 p.m. πŸ”„ Last Modified: May 15, 2025, 8:06 p.m.

7.5

CVSS3.1

CVE-2025-31481 - GraphQL query operations security can be bypassed

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

πŸ“… Published: April 3, 2025, 7:20 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.7

CVSS3.1

CVE-2025-31119 - CWE-470 in generator-jhipster-entity-audit when having Javers selected as Entity Audit Framework

generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath a…

πŸ“… Published: April 3, 2025, 7:11 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3175 - Project Worlds Online Lawyer Management System save_user_edit_profile.php sql injection

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The attack may be launched re…

πŸ“… Published: April 3, 2025, 7 p.m. πŸ”„ Last Modified: May 15, 2025, 8:06 p.m.
Total resulsts: 343738
Page 5485 of 34,374
Β« previous page Β» next page
Filters