5.3

CVSS4.0

CVE-2025-13172 - CodeAstro Gym Management System view-member-report.php sql injection

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the publโ€ฆ

๐Ÿ“… Published: Nov. 14, 2025, 6:02 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:02 p.m.

4.4

CVSS4.0

CVE-2025-4618 - Prisma Browser: Sensitive Information Disclosure Vulnerability in Prisma Browser

A sensitive information disclosure vulnerability in Palo Alto Networks Prismaยฎ Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.

๐Ÿ“… Published: Nov. 14, 2025, 5:53 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 5:53 p.m.

1.1

CVSS4.0

CVE-2025-4617 - Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser

An insufficient policy enforcement vulnerability in Palo Alto Networks Prismaยฎ Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.

๐Ÿ“… Published: Nov. 14, 2025, 5:51 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 5:51 p.m.

1.1

CVSS4.0

CVE-2025-4616 - Prisma Browser: Insufficient Validation of Untrusted Input Vulnerability in Prisma Browser

An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prismaยฎ Browser allows a locally authenticated non-admin user to revert the browserโ€™s security controls.

๐Ÿ“… Published: Nov. 14, 2025, 5:33 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 5:33 p.m.

5.3

CVSS4.0

CVE-2025-13171 - ZZCMS wangkan_list.php sql injection

A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

๐Ÿ“… Published: Nov. 14, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 5:32 p.m.

0.0

CVE-2025-13204 - CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

๐Ÿ“… Published: Nov. 14, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 5:02 p.m.

6.9

CVSS4.0

CVE-2025-13170 - code-projects Simple Online Hotel Reservation System edit_account.php sql injection

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. Theโ€ฆ

๐Ÿ“… Published: Nov. 14, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 4:02 p.m.

5.6

CVSS4.0

CVE-2025-8870 - On affected platforms running Arista EOS, certain serial console input might result in an unexpecteโ€ฆ

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

๐Ÿ“… Published: Nov. 14, 2025, 3:57 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 3:57 p.m.

9.1

CVSS3.1

CVE-2025-64446 -

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPSโ€ฆ

๐Ÿ“… Published: Nov. 14, 2025, 3:50 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 3:50 p.m.

6.9

CVSS4.0

CVE-2025-13169 - code-projects Simple Online Hotel Reservation System add_query_reserve.php sql injection

A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation of the argument room_id leads to sql injection. The attack can be executed remotely. The exploit has โ€ฆ

๐Ÿ“… Published: Nov. 14, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 3:32 p.m.
Total resulsts: 318317
Page 1 of 31,832
ยป next page
Filters