6.9

CVSS4.0

CVE-2025-15198 - code-projects College Notes Uploading System login.php sql injection

A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation of the argument User can lead to sql injection. The attack may be launched remotely. The exploit has been made available to…

πŸ“… Published: Dec. 29, 2025, 5:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

4.8

CVSS3.1

CVE-2025-55064 - Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site S…

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

πŸ“… Published: Dec. 29, 2025, 5:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-68861 - WordPress Plugin Optimizer plugin <= 1.3.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7.

πŸ“… Published: Dec. 29, 2025, 5:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

4.8

CVSS3.1

CVE-2025-55063 - Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site S…

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

πŸ“… Published: Dec. 29, 2025, 5:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-55062 - Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site S…

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

πŸ“… Published: Dec. 29, 2025, 5:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-55061 - Priority - CWE-434 Unrestricted Upload of File with Dangerous Type

CWE-434 Unrestricted Upload of File with Dangerous Type

πŸ“… Published: Dec. 29, 2025, 5:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-55060 - Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

πŸ“… Published: Dec. 29, 2025, 5:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-15197 - code-projects/anirbandutta9 Content Management System/News-Buzz editposts.php unrestricted upload

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotel…

πŸ“… Published: Dec. 29, 2025, 5:02 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 8:50 p.m.

6.9

CVSS4.0

CVE-2025-15196 - code-projects Assessment Management login.php sql injection

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 29, 2025, 4:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:12 a.m.

5.3

CVSS3.1

CVE-2025-53627 - Meshtastic firmware allows forged DMs with no PKC to show up as encrypted

Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the `pki_encrypted` flag is missing, the firmware silently falls back to legacy AES-256-CTR channel encryption. This was an…

πŸ“… Published: Dec. 29, 2025, 4:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:11 p.m.
Total resulsts: 346546
Page 2120 of 34,655
Β« previous page Β» next page
Filters