7.2

CVSS4.0

CVE-2025-54167 - Notification Center

A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following …

πŸ“… Published: Nov. 7, 2025, 3:12 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

2.2

CVSS4.0

CVE-2025-54168 - QuLog Center

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version…

πŸ“… Published: Nov. 7, 2025, 3:12 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

2.2

CVSS4.0

CVE-2025-57706 - File Station 5

A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: File S…

πŸ“… Published: Nov. 7, 2025, 3:11 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4

CVSS4.0

CVE-2025-57712 - Qsync Central

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.…

πŸ“… Published: Nov. 7, 2025, 3:11 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

2.3

CVSS4.0

CVE-2025-58463 - Download Station

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versi…

πŸ“… Published: Nov. 7, 2025, 3:10 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.8

CVSS4.0

CVE-2025-58464 - QuMagie

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QuMagie 2.7.3 and later

πŸ“… Published: Nov. 7, 2025, 3:10 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

2.2

CVSS4.0

CVE-2025-58465 - Download Station

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Dow…

πŸ“… Published: Nov. 7, 2025, 3:09 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

1.2

CVSS4.0

CVE-2025-58469 - QuLog Center

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) …

πŸ“… Published: Nov. 7, 2025, 3:08 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12860 - DedeBIZ freelist_main.php sql injection

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

πŸ“… Published: Nov. 7, 2025, 3:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12859 - DedeBIZ templets_one_edit.php sql injection

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Nov. 7, 2025, 3:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318333
Page 100 of 31,834
Β« previous page Β» next page
Filters