5.1
CVE-2025-41081 - Reflected Cross-Site Scripting (XSS) in IsMyGym
Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL with '/<PATH>.php/<XSS>'. This vulnerability can be exploited to steal sensitive user data, such asβ¦
5.1
CVE-2026-1183 - HTML injection in multiple Botble products
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter.
5.1
CVE-2025-41025 - Stored Cross-Site Scripting in Poultry Farm Management System
Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between parameters and assigned identifiers is as follows:Β Β 'category' y 'product' parameters in '/farm/sell_product.php'.
5.1
CVE-2025-40679 - HTML injection in Isshue from Bdtask
HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to '/category_product_search', affecting the 'product_name' parameter.
5.5
CVE-2025-14369 - CVE-2025-14369
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
5.1
CVE-2025-41024 - Stored Cross-Site Scripting in Poultry Farm Management System
Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between parameters and assigned identifiers is as follows:Β 'companyaddress', 'companyemail', 'companyname', 'country', 'mobilenumβ¦
5.1
CVE-2025-40644 - Reflected Cross-Site Scripting (XSS) in QRGen's Riftzilla
Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'id' parameter in '/article.php'. This vulnerability can be exploited to steal sensitive user dβ¦
0.0
CVE-2026-24023 -
Not used
0.0
CVE-2026-24024 -
Not used
0.0
CVE-2026-24026 -
Not used