High - CVE-2025-7132 - A vulnerability was found in Campcodes Payroll...
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_payroll....
Medium - CVE-2025-7133 - A vulnerability classified as problematic has...
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It...
NA - CVE-2025-26780 - An issue was discovered in L2 in Samsung Mobile...
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.
NA - CVE-2025-32023 - Redis is an open source, in-memory database...
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a...
NA - CVE-2025-43931 - flask-boilerplate through a170e7c allows...
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-43932 - JobCenter through 7e7b0b2 allows account...
JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-43933 - fblog through 983bede allows account takeover...
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-45479 - Insufficient security mechanisms for created...
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.