Show filters
3,806 Total Results
Displaying 31-40 of 3,806
Sort by:
Attacker Value
Unknown
CVE-2025-25355
Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.
0
Attacker Value
Unknown
CVE-2025-25354
Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.
0
Attacker Value
Unknown
CVE-2025-25352
Disclosure Date: February 13, 2025 (last updated February 15, 2025)
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.
0
Attacker Value
Unknown
CVE-2022-31631
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
0
Attacker Value
Unknown
CVE-2025-25351
Disclosure Date: February 12, 2025 (last updated February 15, 2025)
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.
0
Attacker Value
Unknown
CVE-2025-25349
Disclosure Date: February 12, 2025 (last updated February 15, 2025)
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.
0
Attacker Value
Unknown
CVE-2024-48170
Disclosure Date: February 10, 2025 (last updated February 19, 2025)
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
0
Attacker Value
Unknown
CVE-2025-23210
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2025-24374
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
0
Attacker Value
Unknown
CVE-2025-22131
Disclosure Date: January 20, 2025 (last updated January 21, 2025)
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.
0