5.5

CVSS3.1

CVE-2024-58036 - Net::Dropbox::API 1.9 and earlier for Perl uses insecure rand() function for cryptographic functions

Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library which specifically states that it is "Useful mostly for test prograโ€ฆ

๐Ÿ“… Published: April 5, 2025, 4:06 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 10:36 p.m.

5.5

CVSS3.1

CVE-2024-57868 - Web::API 2.8 and earlier for Perl uses insecure rand() function for cryptographic functions

Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random โ€ฆ

๐Ÿ“… Published: April 5, 2025, 3:35 p.m. ๐Ÿ”„ Last Modified: Nov. 13, 2025, 2:38 p.m.

6.7

CVSS3.1

CVE-2025-30401 -

A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachmentโ€™s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitraryโ€ฆ

๐Ÿ“… Published: April 5, 2025, 11:47 a.m. ๐Ÿ”„ Last Modified: April 9, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-3299 - PHPGurukul Men Salon Management System appointment.php sql injection

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /appointment.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has bโ€ฆ

๐Ÿ“… Published: April 5, 2025, 11 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 4:48 p.m.

5.3

CVSS4.0

CVE-2025-3298 - SourceCodester Online Eyewear Shop Registration Master.php access control

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads โ€ฆ

๐Ÿ“… Published: April 5, 2025, 10:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 4:49 p.m.

5.1

CVSS4.0

CVE-2025-3297 - SourceCodester Online Eyewear Shop Master.php cross site scripting

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remoteโ€ฆ

๐Ÿ“… Published: April 5, 2025, 8:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 4:49 p.m.

5.3

CVSS4.0

CVE-2025-3296 - SourceCodester Online Eyewear Shop Users.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely.โ€ฆ

๐Ÿ“… Published: April 5, 2025, 8 a.m. ๐Ÿ”„ Last Modified: April 8, 2025, 4:49 p.m.

9.8

CVSS3.1

CVE-2025-2941 - Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arโ€ฆ

๐Ÿ“… Published: April 5, 2025, 7:01 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2025-2789 - MultiVendorX โ€“ The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorโ€ฆ

The MultiVendorX โ€“ Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace โ€“ Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and inโ€ฆ

๐Ÿ“… Published: April 5, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 11:30 p.m.

4.3

CVSS3.1

CVE-2025-1233 - Lafka Plugin <= 7.1.0 - Missing Authorization to Authenticated (Subscriber+) Theme Option Update

The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the thโ€ฆ

๐Ÿ“… Published: April 5, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 9:30 p.m.
Total resulsts: 349182
Page 6002 of 34,919
ยซ previous page ยป next page
Filters