Show filters
1,063 Total Results
Displaying 21-30 of 1,063
Sort by:
Attacker Value
Unknown
CVE-2025-25241
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.
0
Attacker Value
Unknown
CVE-2025-24336
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.
0
Attacker Value
Unknown
CVE-2025-0844
Disclosure Date: January 30, 2025 (last updated February 05, 2025)
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file signup.php of the component Registration Page. The manipulation of the argument firstname/lastname/email/borrow/user_address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
0
Attacker Value
Unknown
CVE-2025-0843
Disclosure Date: January 29, 2025 (last updated February 05, 2025)
A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unknown function of the file admindashboard.php of the component Admin Panel. The manipulation of the argument email/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2025-0851
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.
0
Attacker Value
Unknown
CVE-2025-0842
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2025-24728
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library allows Blind SQL Injection. This issue affects Bug Library: from n/a through 2.1.4.
0
Attacker Value
Unknown
CVE-2025-22768
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Media Library Mime Type allows Stored XSS. This issue affects Rocket Media Library Mime Type: from n/a through 2.1.0.
0
Attacker Value
Unknown
CVE-2025-23580
Disclosure Date: January 21, 2025 (last updated January 22, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2025-24012
Disclosure Date: January 21, 2025 (last updated February 21, 2025)
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.
0