6.3

CVSS4.0

CVE-2025-12874 - HTTP Request Smuggling in Quest Coexistence Manager for Notes

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an attacker toΒ bypass ac…

πŸ“… Published: Dec. 19, 2025, 7:36 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:52 p.m.

6.9

CVSS4.0

CVE-2025-14967 - itsourcecode Student Management System candidates_report.php sql injection

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /candidates_report.php. The manipulation of the argument school_year leads to sql injection. The attack can be initiated remotely. The exploit is publ…

πŸ“… Published: Dec. 19, 2025, 7:32 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 3:03 p.m.

5.1

CVSS4.0

CVE-2025-14966 - FastAdmin Backend Controller Backend.php selectpage sql injection

A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing a manipulation of the argument custom/searchField can lead to sql injection. It is possible to l…

πŸ“… Published: Dec. 19, 2025, 7:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

5.1

CVSS4.0

CVE-2025-14965 - 1541492390c yougou-mall ResourceController.java delete path traversal

A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the function upload/delete of the file src/main/java/per/ccm/ygmall/extra/controller/ResourceController.java. Performing manipulation results in path traversal. This product is using a …

πŸ“… Published: Dec. 19, 2025, 7:02 p.m. πŸ”„ Last Modified: Dec. 27, 2025, 8:15 p.m.

9.3

CVSS4.0

CVE-2025-14964 - TOTOLINK T10 cstecgi.cgi sprintf stack-based overflow

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.

πŸ“… Published: Dec. 19, 2025, 7:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:58 a.m.

5.3

CVSS4.0

CVE-2025-14962 - code-projects Simple Stock System chatuser.php cross site scripting

A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.

πŸ“… Published: Dec. 19, 2025, 6:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

6.9

CVSS4.0

CVE-2025-14961 - code-projects Simple Blood Donor Management System editedcampaign.php sql injection

A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /editedcampaign.php. The manipulation of the argument campaignname results in sql injection. The attack can be executed remotely. The exploit is now public…

πŸ“… Published: Dec. 19, 2025, 6:32 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 6:14 p.m.

6.9

CVSS4.0

CVE-2025-14960 - code-projects Simple Blood Donor Management System editeddonor.php sql injection

A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /editeddonor.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been discl…

πŸ“… Published: Dec. 19, 2025, 6:02 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 5:55 p.m.

6.9

CVSS4.0

CVE-2025-14959 - code-projects Simple Stock System signup.php sql injection

A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available t…

πŸ“… Published: Dec. 19, 2025, 6:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

4.8

CVSS4.0

CVE-2025-14958 - floooh sokol sokol_gfx.h _sg_pipeline_common_init heap-based overflow

A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library sokol_gfx.h. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. …

πŸ“… Published: Dec. 19, 2025, 5:32 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 6:33 p.m.
Total resulsts: 343168
Page 1893 of 34,317
Β« previous page Β» next page
Filters