8.7

CVSS4.0

CVE-2025-15089 - UTT 进取 512W APSecurity strcpy buffer overflow

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and m…

📅 Published: Dec. 25, 2025, 10:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 6:56 p.m.

5.3

CVSS4.0

CVE-2025-15088 - ketr JEPaaS loadPostil postilService.loadPostils sql injection

A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation of the argument keyWord results in sql injection. Remote exploitation of the attack is possible. The …

📅 Published: Dec. 25, 2025, 10:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15087 - youlaitech youlai-mall OrderController.java submitOrderPayment improper authorization

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn leads to improper authorizatio…

📅 Published: Dec. 25, 2025, 9:02 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:22 p.m.

5.3

CVSS4.0

CVE-2025-15086 - youlaitech youlai-mall MemberController.java getMemberByMobile access control

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remo…

📅 Published: Dec. 25, 2025, 8:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 8:02 p.m.

6.4

CVSS3.1

CVE-2025-68936 -

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

📅 Published: Dec. 25, 2025, 8:07 p.m. 🔄 Last Modified: Jan. 2, 2026, 7:36 p.m.

6.4

CVSS3.1

CVE-2025-68935 -

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

📅 Published: Dec. 25, 2025, 8:05 p.m. 🔄 Last Modified: Jan. 2, 2026, 7:37 p.m.

5.3

CVSS4.0

CVE-2025-15085 - youlaitech youlai-mall Balance MemberController.java deductBalance improper authorization

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The manipulation results in improper authorizatio…

📅 Published: Dec. 25, 2025, 7:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 8:02 p.m.

2.3

CVSS4.0

CVE-2025-15084 - youlaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control

A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java of the component Order Payment Handler. The manipulation leads to impr…

📅 Published: Dec. 25, 2025, 6:32 p.m. 🔄 Last Modified: Dec. 31, 2025, 7:50 p.m.

1

CVSS4.0

CVE-2025-15083 - TOZED ZLT M30s UART on-chip debug and test interface with improper access control

A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test interface with improper access control. The physical device can be targeted for the attack. Attacks of …

📅 Published: Dec. 25, 2025, 5:32 p.m. 🔄 Last Modified: Jan. 20, 2026, 7:35 p.m.

6.9

CVSS4.0

CVE-2025-15082 - TOZED ZLT M30s Web Management proc_post information disclosure

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The e…

📅 Published: Dec. 25, 2025, 5:02 p.m. 🔄 Last Modified: Jan. 20, 2026, 7:54 p.m.
Total resulsts: 345299
Page 2018 of 34,530
« previous page » next page
Filters