CVE-2025-3348 - Code-projects Patient Record Management System SQL Injection Vulnerability
CVE ID : CVE-2025-3348
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3348
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3349 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3349
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3349
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30373 - Graylog HTTP Input Authentication Bypass Vulnerability
CVE ID : CVE-2025-30373
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-30373
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31138 - Tarteaucitron.js Clickjacking Vulnerability
CVE ID : CVE-2025-31138
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements (clickjacking), or disrupt the intended functionality and accessibility of the website. This vulnerability is fixed in 1.20.1.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31138
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements (clickjacking), or disrupt the intended functionality and accessibility of the website. This vulnerability is fixed in 1.20.1.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31475 - "Tarteaucitron.js Prototype Pollution Vulnerability"
CVE ID : CVE-2025-31475
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this vulnerability to modify object prototypes, affecting core JavaScript behavior, cause application crashes or unexpected behavior, or potentially introduce further security vulnerabilities depending on the application's architecture. This vulnerability is fixed in 1.20.1.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31475
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this vulnerability to modify object prototypes, affecting core JavaScript behavior, cause application crashes or unexpected behavior, or potentially introduce further security vulnerabilities depending on the application's architecture. This vulnerability is fixed in 1.20.1.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31476 - Tarteaucitron.js JavaScript URL Scheme Injection
CVE ID : CVE-2025-31476
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31476
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32014 - Estree-util-value-to-estree Prototype Pollution
CVE ID : CVE-2025-32014
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-32014
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3248 - Langflow Code Injection Vulnerability
CVE ID : CVE-2025-3248
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3248
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3371 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3371
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3371
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3372 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3372
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3372
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28400 - Apache Struts Privilege Escalation Vulnerability
CVE ID : CVE-2025-28400
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28400
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28401 - "RUoYi Privilege Escalation Vulnerability"
CVE ID : CVE-2025-28401
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28401
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28402 - Ruyi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28402
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28402
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28403 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28403
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28403
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28405 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28405
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28405
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28406 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28406
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28406
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28407 - Apache RUoYi Unauthenticated Privilege Escalation Vulnerability
CVE ID : CVE-2025-28407
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28407
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28408 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28408
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28408
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28409 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28409
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28409
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28410 - "RUoYi Privilege Escalation Vulnerability"
CVE ID : CVE-2025-28410
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28410
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28411 - RUoYi RCE
CVE ID : CVE-2025-28411
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28411
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...