6.1

CVSS3.1

CVE-2025-61319 -

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can b…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

6.5

CVSS3.1

CVE-2025-60868 -

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollu…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

0.0

CVE-2025-60305 -

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

0.0

CVE-2025-60307 -

code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

0.0

CVE-2025-60268 -

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 5:49 p.m.

0.0

CVE-2025-61505 -

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could le…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:34 p.m.

0.0

CVE-2025-55903 -

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 7:19 p.m.

6.5

CVSS3.1

CVE-2025-61152 -

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthori…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

0.0

CVE-2025-60308 -

code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. Malicious JavaScript code is entered in the Description field, which can leak the administrator's cookie information when browsing…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 5:47 p.m.

8.3

CVSS3.1

CVE-2025-60880 -

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in th…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:28 p.m.
Total resulsts: 313760
Page 22 of 31,376
Β« previous page Β» next page
Filters