6.3

CVSS4.0

CVE-2025-14276 - Ilevia EVE X1 Server leaf_search.php command injection

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is needed for the atta…

πŸ“… Published: Dec. 8, 2025, 9:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

2.7

CVSS3.1

CVE-2025-36102 - IBM Controller Validation Bypass

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

πŸ“… Published: Dec. 8, 2025, 9:30 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 6:14 p.m.

4.3

CVSS3.1

CVE-2025-33111 - IBM Controller Information Disclosure

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose sensitive information to an authenticated user due to race condition attacks.

πŸ“… Published: Dec. 8, 2025, 9:28 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 6:13 p.m.

6.5

CVSS3.1

CVE-2025-36015 - IBM Controller Denial of Service

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.

πŸ“… Published: Dec. 8, 2025, 9:22 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 6:11 p.m.

0.0

CVE-2025-67503 -

This CVE is a duplicate of another CVE.

πŸ“… Published: Dec. 8, 2025, 9:19 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 12:01 a.m.

0.0

CVE-2025-67497 -

Further research determined the issue is not a vulnerability.

πŸ“… Published: Dec. 8, 2025, 8:58 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 10:54 p.m.

0.0

CVE-2025-67498 -

Further research determined the issue is not a vulnerability.

πŸ“… Published: Dec. 8, 2025, 8:58 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 10:58 p.m.

7.1

CVSS3.1

CVE-2025-14261 - Lack of entropy allows registered low-privileged users of Litmus to crack valid JWT tokens and gain…

The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.

πŸ“… Published: Dec. 8, 2025, 6:12 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-14259 - Jihai Jshop MiniProgram Mall System api.html sql injection

A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functionality of the file /index.php/api.html. The manipulation of the argument cat_id results in sql injection. The attack may be launched remotely. The exploit has been made public and c…

πŸ“… Published: Dec. 8, 2025, 6:02 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 10:26 a.m.

6.9

CVSS4.0

CVE-2025-14258 - itsourcecode Student Management System newsubject.php sql injection

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /newsubject.php. The manipulation of the argument sub leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to …

πŸ“… Published: Dec. 8, 2025, 5:32 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:06 p.m.
Total resulsts: 343921
Page 2244 of 34,393
Β« previous page Β» next page
Filters