9.8

CVSS3.1

CVE-2025-61548 -

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterizati…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

8.7

CVSS3.1

CVE-2025-63611 -

Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=<id>). When an administrator opens the complaint, inj…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 12, 2026, 6:45 p.m.

9.1

CVSS3.1

CVE-2025-68715 -

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 30, 2026, 1:04 a.m.

6.1

CVSS3.1

CVE-2025-61549 -

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allow…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-67325 -

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 30, 2026, 1:06 a.m.

5.4

CVSS3.1

CVE-2025-61550 -

Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). User-supplied input is stored and later rendered in HTML pages without p…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

6.8

CVSS3.1

CVE-2025-61547 -

Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unkno…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

5.5

CVSS3.1

CVE-2025-67825 -

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 2, 2026, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-67091 -

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 16, 2026, 9:28 p.m.

5.1

CVSS3.1

CVE-2025-67090 -

The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local net…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 16, 2026, 9:28 p.m.
Total resulsts: 346710
Page 1991 of 34,671
« previous page » next page
Filters