0.0

CVE-2025-63544 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 8:28 p.m.

0.0

CVE-2025-63543 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 8:26 p.m.

0.0

CVE-2025-63639 -

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing th…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 8:05 p.m.

0.0

CVE-2025-63687 -

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 3:43 p.m.

0.0

CVE-2025-63686 -

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 3:49 p.m.

0.0

CVE-2025-63784 -

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing a…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 4:13 p.m.

0.0

CVE-2025-63689 -

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 3:33 p.m.

0.0

CVE-2025-63785 -

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a text element. An atta…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 4:33 p.m.

0.0

CVE-2025-63783 -

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user f…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 4 p.m.

0.0

CVE-2025-63714 -

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of us…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 5:49 p.m.
Total resulsts: 317427
Page 15 of 31,743
Β« previous page Β» next page
Filters