5.3

CVSS4.0

CVE-2025-11449 - Reflected Cross Site Scripting in ServiceNow AI Platform

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.Β Β Β  ServiceNow has addressed…

πŸ“… Published: Oct. 10, 2025, 1:15 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:35 p.m.

5.3

CVSS4.0

CVE-2025-11450 - Reflected Cross Site Scripting in ServiceNow AI Platform

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this…

πŸ“… Published: Oct. 10, 2025, 1:09 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 1:09 a.m.

9.4

CVSS3.1

CVE-2025-60269 -

JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:11 p.m.

0.0

CVE-2025-60308 -

code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. Malicious JavaScript code is entered in the Description field, which can leak the administrator's cookie information when browsing…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 5:47 p.m.

0.0

CVE-2025-61505 -

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could le…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:34 p.m.

7.3

CVSS3.1

CVE-2025-60869 -

Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visi…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

0.0

CVE-2025-60268 -

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 5:49 p.m.

8.3

CVSS3.1

CVE-2025-60880 -

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in th…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:28 p.m.

8.1

CVSS3.1

CVE-2025-60378 -

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email …

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 9:17 p.m.

4.3

CVSS3.1

CVE-2025-62292 -

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:17 a.m.
Total resulsts: 313747
Page 20 of 31,375
Β« previous page Β» next page
Filters