CVE-2025-8329
published 2025-07-30CVE-2025-8329: A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.65%
46.9th percentile
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | vehicle_management | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-21752 kernel: btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
bugzilla·2025-02-27·CVSS 5.5
CVE-2025-21752 [MEDIUM] CVE-2025-21752 kernel: btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
CVE-2025-21752 kernel: btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
In the Linux kernel, the following vulnerability has been resolved:
btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
Don't use btrfs_set_item_key_safe() to modify the keys in the RAID
stripe-tree, as this can lead to corruption of the tree, which is caught
by the checks in btrfs_set_item_key_safe():
BTRFS info (device nvme1n1): leaf 49168384 gen 15 total ptrs 194 free space 8329 owner 12
BTRFS info (device nvme1n1): refs 2 lock_owner 1030 current 1030
[ snip ]
item 105 key (354549760 230 20480) itemoff 14587 itemsize 16
stride 0 devid 5 physical 67502080
item 106 key (354631680 230 4096) itemoff 14571 itemsize 16
stride 0 devid 1 physical 88559616
item 107 key (354631680 230 32768) ite
Bugzilla
CVE-2024-40094 graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java
bugzilla·2024-07-30·CVSS 5.3
CVE-2024-40094 [MEDIUM] CVE-2024-40094 graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java
CVE-2024-40094 graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
Discussion:
This issue has been addressed in the following products:
Cryostat 3 on RHEL 8
Via RHSA-2024:8329 https://access.redhat.com/errata/RHSA-2024:8329
---
This issue has been addressed in the following products:
RHOSS-1.35-RHEL-8
Via RHSA-2025:0664 https://access.redhat.com/errata/RHSA-2025:0664
2025-07-30
Published