Show filters
3,806 Total Results
Displaying 31-40 of 3,806
Sort by:
Attacker Value
Unknown

CVE-2025-25355

Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.
Attacker Value
Unknown

CVE-2025-25354

Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.
Attacker Value
Unknown

CVE-2025-25352

Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.
Attacker Value
Unknown

CVE-2022-31631

Disclosure Date: February 12, 2025 (last updated February 13, 2025)
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
0
Attacker Value
Unknown

CVE-2025-25351

Disclosure Date: February 12, 2025 (last updated February 15, 2025)
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.
Attacker Value
Unknown

CVE-2025-25349

Disclosure Date: February 12, 2025 (last updated February 15, 2025)
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.
Attacker Value
Unknown

CVE-2024-48170

Disclosure Date: February 10, 2025 (last updated February 19, 2025)
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
Attacker Value
Unknown

CVE-2025-23210

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown

CVE-2025-24374

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
0
Attacker Value
Unknown

CVE-2025-22131

Disclosure Date: January 20, 2025 (last updated January 21, 2025)
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.
0