6.9
CVE-2025-1959 - Codezips Gym Management System change_s_pwd.php sql injection
A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The manipulation of the argument login_id/login_key leads to sql injection. It is possible to launch the attack remotely. The exploit haβ¦
5.3
CVE-2025-1958 - aaluoxiang oa_system address-mapper.xml sql injection
A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql injection. The attack may be initiated remotely.β¦
5.1
CVE-2025-1957 - code-projects Blood Bank System o+.php cross site scripting
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /BBfile/Blood/o+.php. The manipulation of the argument Bloodname leads to cross site scripting. The attack can be initiated remotely. The exploit has been β¦
9.3
CVE-2025-27510 - RCE in the package conda-forge-metadata
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remoβ¦
6.9
CVE-2025-1956 - code-projects Shopping Portal Login index.php sql injection
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. Thβ¦
5.1
CVE-2025-1955 - code-projects Online Class and Exam Scheduling System profile.php cross site scripting
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scriptinβ¦
6.9
CVE-2025-1954 - PHPGurukul Human Metapneumovirus Testing Management System login.php sql injection
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username leads to sql injection. The attack can be launcβ¦
5.3
CVE-2024-8000 - On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur whereβ¦
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captiveβ¦
5.3
CVE-2024-9135 - On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause thβ¦
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.
7.2
CVE-2025-1080 - Macro URL arbitrary script execution
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with aβ¦