5.3

CVSS4.0

CVE-2025-15135 - joey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookie…

A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched …

📅 Published: Dec. 28, 2025, 12:02 p.m. 🔄 Last Modified: Dec. 29, 2025, 5:58 p.m.

5.1

CVSS4.0

CVE-2025-15134 - yourmaileyes MOOC Submission MainController.java subreview cross site scripting

A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performing manipulation of the argument review results in cross site scripting. The attack can be initiated r…

📅 Published: Dec. 28, 2025, 11:32 a.m. 🔄 Last Modified: Dec. 29, 2025, 5:59 p.m.

5.3

CVSS4.0

CVE-2025-15133 - ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection

A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit…

📅 Published: Dec. 28, 2025, 11:02 a.m. 🔄 Last Modified: Jan. 7, 2026, 9:38 p.m.

5.3

CVSS4.0

CVE-2025-15132 - ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection

A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has b…

📅 Published: Dec. 28, 2025, 10:32 a.m. 🔄 Last Modified: Jan. 7, 2026, 9:42 p.m.

5.3

CVSS4.0

CVE-2025-15131 - ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection

A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation results in command injection. The attack may be performed from remote. The exploit has been made publ…

📅 Published: Dec. 28, 2025, 10:02 a.m. 🔄 Last Modified: Jan. 7, 2026, 9:39 p.m.

5.1

CVSS4.0

CVE-2025-15130 - shanyu SyCms Administrative Panel FileManageController.class.php addPost code injection

A vulnerability has been found in shanyu SyCms up to a242ef2d194e8bb249dc175e7c49f2c1673ec921. This issue affects the function addPost of the file Application/Admin/Controller/FileManageController.class.php of the component Administrative Panel. The manipulation leads to code injection. The attack …

📅 Published: Dec. 28, 2025, 9:32 a.m. 🔄 Last Modified: Dec. 29, 2025, 6:01 p.m.

5.3

CVSS4.0

CVE-2025-15129 - ChenJinchuang Lin-CMS-TP5 File Upload LocalUploader.php upload code injection

A flaw has been found in ChenJinchuang Lin-CMS-TP5 up to 0.3.3. This vulnerability affects the function Upload of the file application/lib/file/LocalUploader.php of the component File Upload Handler. Executing manipulation of the argument File can lead to code injection. The attack can be executed …

📅 Published: Dec. 28, 2025, 9:02 a.m. 🔄 Last Modified: Dec. 29, 2025, 6:55 p.m.

6.9

CVSS4.0

CVE-2025-15128 - ZKTeco BioTime Endpoint safe_setting credentials storage

A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_setting/ of the component Endpoint. Performing a manipulation of the argument backup_encryption_password_decrypt/export_encryption_password_decrypt results in unprotected stor…

📅 Published: Dec. 28, 2025, 8:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

6.9

CVSS4.0

CVE-2025-15127 - FantasticLBP Hotels_Server Room.php sql injection

A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the argument hotelId leads to sql injection. The attack may be lau…

📅 Published: Dec. 28, 2025, 8:02 a.m. 🔄 Last Modified: March 8, 2026, 1:52 a.m.

2.3

CVSS4.0

CVE-2025-15126 - JeecgBoot getPositionUserList improper authorization

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity…

📅 Published: Dec. 28, 2025, 7:32 a.m. 🔄 Last Modified: Dec. 30, 2025, 7:13 p.m.
Total resulsts: 343923
Page 1871 of 34,393
« previous page » next page
Filters