5.1

CVSS4.0

CVE-2025-4006 - youyiio BeyongCms Document Management Page Upload.html unrestricted upload

A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document Management Page. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack r…

πŸ“… Published: April 28, 2025, 7 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4005 - PHPGurukul COVID19 Testing Management System patient-report.php sql injection

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /patient-report.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exp…

πŸ“… Published: April 28, 2025, 6:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:30 p.m.

6.9

CVSS4.0

CVE-2025-4004 - PHPGurukul COVID19 Testing Management System password-recovery.php sql injection

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. The attack can be initiated remote…

πŸ“… Published: April 28, 2025, 6 a.m. πŸ”„ Last Modified: May 12, 2025, 7:30 p.m.

3.5

CVSS3.1

CVE-2025-0627 - AI Autotagger < 3.30.0 - Admin+ Stored XSS

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo…

πŸ“… Published: April 28, 2025, 6 a.m. πŸ”„ Last Modified: April 30, 2025, 6:29 p.m.

3.5

CVSS3.1

CVE-2024-9771 - WP-Recall < 16.26.12 - Admin+ Stored XSS

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 28, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 9:09 p.m.

5.3

CVSS3.1

CVE-2024-13688 - Admin and Site Enhancements (ASE) < 7.6.10 - Password Protection Bypass

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request

πŸ“… Published: April 28, 2025, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon

6.8

CVSS4.0

CVE-2025-4003 - RefindPlusRepo RefindPlus RP_ApfsIo.c InternalApfsTranslateBlock null pointer dereference

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the lo…

πŸ“… Published: April 28, 2025, 5:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-4002 - RefindPlusRepo RefindPlus BootLog.c GetDebugLogFile null pointer dereference

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The patch is identi…

πŸ“… Published: April 28, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-4001 - scipopt scip File Descriptor genRandomLOPInstance.c main file descriptor consumption

A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the file examples/LOP/src/genRandomLOPInstance.c of the component File Descriptor Handler. The manipulation of the argument File leads to uncontrolled fil…

πŸ“… Published: April 28, 2025, 4:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-4000 - Seeyon Zhiyuan OA Web Application System ssoproxy.jsp cross site scripting

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\ssoproxy\jsp\ssoproxy.jsp. The manipulation of the argument Name leads to cross site sc…

πŸ“… Published: April 28, 2025, 4 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 4:23 p.m.
Total resulsts: 349182
Page 5648 of 34,919
Β« previous page Β» next page
Filters