7.5

CVSS3.1

CVE-2024-53868 - Apache Traffic Server: Malformed chunked message body allows request smuggling

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.

📅 Published: April 3, 2025, 8:59 a.m. 🔄 Last Modified: April 29, 2025, 8:42 p.m.

5.1

CVSS4.0

CVE-2025-3152 - caipeichao ThinkOX Search search.html cross site scripting

A vulnerability classified as problematic has been found in caipeichao ThinkOX 1.0. This affects an unknown part of the file /ThinkOX-master/index.php?s=/Weibo/Index/search.html of the component Search. The manipulation of the argument keywords leads to cross site scripting. It is possible to initi…

📅 Published: April 3, 2025, 8 a.m. 🔄 Last Modified: April 7, 2025, 2:18 p.m.

6.9

CVSS4.0

CVE-2025-3151 - SourceCodester Gym Management System signup.php sql injection

A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The attack may be launched remotely. The exploit has…

📅 Published: April 3, 2025, 8 a.m. 🔄 Last Modified: May 14, 2025, 9:06 p.m.

5.3

CVSS4.0

CVE-2025-3150 - itning Student Homework Management System cross-site request forgery

A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclo…

📅 Published: April 3, 2025, 7:31 a.m. 🔄 Last Modified: Aug. 13, 2025, 12:51 a.m.

4.8

CVSS4.0

CVE-2025-3149 - itning Student Homework Management System Edit Job Page fileupload cross site scripting

A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been classified as problematic. Affected is an unknown function of the file /shw_war/fileupload of the component Edit Job Page. The manipulation of the argument Course leads to cross site scripting. It is pos…

📅 Published: April 3, 2025, 7:31 a.m. 🔄 Last Modified: Aug. 13, 2025, 12:53 a.m.

6.4

CVSS3.1

CVE-2025-1663 - Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Script…

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: April 3, 2025, 7:21 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

4.4

CVSS3.1

CVE-2025-2874 - User Submitted Posts <= 20241026 - Authenticated (Admin+) Stored Cross-Site Scripting

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input sanitization and output escaping. This makes it possible for authe…

📅 Published: April 3, 2025, 7:21 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

6.4

CVSS3.1

CVE-2024-13673 - Big Boom Directory <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: April 3, 2025, 7:21 a.m. 🔄 Last Modified: April 8, 2026, 4:52 p.m.

4.8

CVSS4.0

CVE-2025-3148 - codeprojects Product Management System Login buffer overflow

A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affects some unknown processing of the component Login. The manipulation of the argument Str1 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclose…

📅 Published: April 3, 2025, 7 a.m. 🔄 Last Modified: May 7, 2025, 4:18 p.m.

6.9

CVSS4.0

CVE-2025-3147 - PHPGurukul Boat Booking System add-subadmin.php sql injection

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. The attack can be initiated remotely. The exploit has been …

📅 Published: April 3, 2025, 7 a.m. 🔄 Last Modified: May 7, 2025, 4:19 p.m.
Total resulsts: 343923
Page 5513 of 34,393
« previous page » next page
Filters