A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/post-avehical.php. The manipulation of the argument img1/img2/img3/img4/img5 leads to unrestricted upload.
This vulnerability is handled as CVE-2025-4926. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection.
This vulnerability is known as CVE-2025-4925. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection.
This vulnerability is traded as CVE-2025-4924. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-4923. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Mozilla Firefox up to 138.0.3. This vulnerability affects unknown code of the component Javascript Object Handler. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2025-4920. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Mozilla Firefox ESR up to 115.23.0. This affects an unknown part of the component Javascript Object Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2025-4919. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Firefox ESR up to 115.23.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component JavaScript Handler. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2025-4918. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in donetick up to 0.1.43. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component JSON Web Token Handler. The manipulation leads to insecure default variable initialization.
This vulnerability is known as CVE-2025-47945. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.