0.0

CVE-2026-21649 -

Not used

πŸ“… Published: Jan. 2, 2026, 8:41 a.m. πŸ”„ Last Modified: Jan. 3, 2026, 3:55 a.m.

0.0

CVE-2026-21648 -

Not used

πŸ“… Published: Jan. 2, 2026, 8:41 a.m. πŸ”„ Last Modified: Jan. 3, 2026, 3:55 a.m.

0.0

CVE-2026-21652 -

Not used

πŸ“… Published: Jan. 2, 2026, 8:41 a.m. πŸ”„ Last Modified: Jan. 3, 2026, 3:55 a.m.

0.0

CVE-2026-21644 -

Not used

πŸ“… Published: Jan. 2, 2026, 8:41 a.m. πŸ”„ Last Modified: Jan. 3, 2026, 3:55 a.m.

5.1

CVSS4.0

CVE-2025-15437 - LigeroSmart Environment Variable cross site scripting

A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could …

πŸ“… Published: Jan. 2, 2026, 8:32 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 3:39 a.m.

6.9

CVSS4.0

CVE-2025-15436 - Yonyou KSOA work_edit.jsp sql injection

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be…

πŸ“… Published: Jan. 2, 2026, 8:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:09 a.m.

6.9

CVSS4.0

CVE-2025-15435 - Yonyou KSOA work_update.jsp sql injection

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendo…

πŸ“… Published: Jan. 2, 2026, 7:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:08 a.m.

6.9

CVSS4.0

CVE-2025-15434 - Yonyou KSOA PrintZPYG.jsp sql injection

A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early a…

πŸ“… Published: Jan. 2, 2026, 7:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:08 a.m.

6.9

CVSS4.0

CVE-2025-15432 - yeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile …

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadShowFile of the file /file/downloadShowFile.action of the component com.yeqifu.sys.controller.FileController. The manipulation of the argument path lead…

πŸ“… Published: Jan. 2, 2026, 6:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

8.7

CVSS4.0

CVE-2025-15431 - UTT 进取 512W formFtpServerDirConfig strcpy buffer overflow

A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDirConfig. Executing a manipulation of the argument filename can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used. The ven…

πŸ“… Published: Jan. 2, 2026, 6:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.
Total resulsts: 347586
Page 2148 of 34,759
Β« previous page Β» next page
Filters