6.9

CVSS4.0

CVE-2025-3175 - Project Worlds Online Lawyer Management System save_user_edit_profile.php sql injection

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The attack may be launched re…

πŸ“… Published: April 3, 2025, 7 p.m. πŸ”„ Last Modified: May 15, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-3174 - Project Worlds Online Lawyer Management System searchLawyer.php sql injection

A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to sql injection. The attack can be launched r…

πŸ“… Published: April 3, 2025, 7 p.m. πŸ”„ Last Modified: April 23, 2025, 3:02 p.m.

7.7

CVSS3.1

CVE-2025-31487 - The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server

The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns an XML specifying a …

πŸ“… Published: April 3, 2025, 6:38 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3173 - Project Worlds Online Lawyer Management System save_booking.php sql injection

A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id/description leads to sql injection. It is possible to launch the attack remot…

πŸ“… Published: April 3, 2025, 6:31 p.m. πŸ”„ Last Modified: Sept. 27, 2025, 12:33 a.m.

5.3

CVSS3.1

CVE-2025-31486 - Vite allows server.fs.deny to be bypassed with .svg or relative paths

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than bu…

πŸ“… Published: April 3, 2025, 6:24 p.m. πŸ”„ Last Modified: July 13, 2025, 11:06 a.m.

4.8

CVSS4.0

CVE-2025-31483 - Stored XSS in Miniflux Media Proxy due to improper Content-Security-Policy configuration

Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy has been changed fr…

πŸ“… Published: April 3, 2025, 6:07 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3172 - Project Worlds Online Lawyer Management System lawyer_booking.php sql injection

A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyer_booking.php. The manipulation of the argument unblock_id leads to sql injection. The attack may be initiated remote…

πŸ“… Published: April 3, 2025, 6 p.m. πŸ”„ Last Modified: May 15, 2025, 8:07 p.m.

6.9

CVSS4.0

CVE-2025-3171 - Project Worlds Online Lawyer Management System approve_lawyer.php sql injection

A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injection. The attack can be initiated remotely. The exploit has …

πŸ“… Published: April 3, 2025, 6 p.m. πŸ”„ Last Modified: April 8, 2025, 8:43 p.m.

5.3

CVSS3.1

CVE-2025-31126 - Element X iOS allows the entity in control of the well-known file to break the confidentiality of e…

Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This vulnerability is…

πŸ“… Published: April 3, 2025, 5:54 p.m. πŸ”„ Last Modified: April 7, 2025, 6:24 p.m.

5.3

CVSS3.1

CVE-2025-31127 - Element X Android allows the entity in control of the well-known file to break the confidentiality …

Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25.03.3, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This …

πŸ“… Published: April 3, 2025, 5:54 p.m. πŸ”„ Last Modified: April 7, 2025, 6:24 p.m.
Total resulsts: 343919
Page 5504 of 34,392
Β« previous page Β» next page
Filters