8.7

CVSS4.0

CVE-2025-15091 - UTT 进取 512W formPictureUrl strcpy buffer overflow

A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly discl…

📅 Published: Dec. 25, 2025, 11:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 6:56 p.m.

5.3

CVSS3.1

CVE-2025-14913 - Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitra…

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthe…

📅 Published: Dec. 25, 2025, 11:20 p.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

8.7

CVSS4.0

CVE-2025-15090 - UTT 进取 512W formConfigNoticeConfig strcpy buffer overflow

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public an…

📅 Published: Dec. 25, 2025, 11:02 p.m. 🔄 Last Modified: Dec. 31, 2025, 6:56 p.m.

8.7

CVSS4.0

CVE-2025-15089 - UTT 进取 512W APSecurity strcpy buffer overflow

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and m…

📅 Published: Dec. 25, 2025, 10:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 6:56 p.m.

5.3

CVSS4.0

CVE-2025-15088 - ketr JEPaaS loadPostil postilService.loadPostils sql injection

A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation of the argument keyWord results in sql injection. Remote exploitation of the attack is possible. The …

📅 Published: Dec. 25, 2025, 10:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-15087 - youlaitech youlai-mall OrderController.java submitOrderPayment improper authorization

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn leads to improper authorizatio…

📅 Published: Dec. 25, 2025, 9:02 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:22 p.m.

5.3

CVSS4.0

CVE-2025-15086 - youlaitech youlai-mall MemberController.java getMemberByMobile access control

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remo…

📅 Published: Dec. 25, 2025, 8:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 8:02 p.m.

6.4

CVSS3.1

CVE-2025-68936 -

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

📅 Published: Dec. 25, 2025, 8:07 p.m. 🔄 Last Modified: Jan. 2, 2026, 7:36 p.m.

6.4

CVSS3.1

CVE-2025-68935 -

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

📅 Published: Dec. 25, 2025, 8:05 p.m. 🔄 Last Modified: Jan. 2, 2026, 7:37 p.m.

5.3

CVSS4.0

CVE-2025-15085 - youlaitech youlai-mall Balance MemberController.java deductBalance improper authorization

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The manipulation results in improper authorizatio…

📅 Published: Dec. 25, 2025, 7:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 8:02 p.m.
Total resulsts: 343920
Page 1880 of 34,392
« previous page » next page
Filters