0.0

CVE-2025-67285 -

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleanin…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 4:14 p.m.

7.2

CVSS3.1

CVE-2025-66923 -

A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2025-65185 -

There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 4:17 p.m.

7.2

CVSS3.1

CVE-2025-67172 -

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2024-29371 -

In jose4j before 0.9.5, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during …

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 3:56 p.m.

0.0

CVE-2024-29370 -

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significan…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 3:49 p.m.

0.0

CVE-2022-23851 -

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 2:54 p.m.

0.0

CVE-2025-67174 -

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:42 p.m.

0.0

CVE-2024-46060 -

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary comma…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:42 p.m.

0.0

CVE-2025-67074 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:15 p.m.
Total resulsts: 322971
Page 18 of 32,298
Β« previous page Β» next page
Filters