6.9

CVSS4.0

CVE-2025-13442 - UTT 进取 750W formPdbUpConfig system command injection

A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argument policyNames leads to command injection. The attack may be launched remotely. The exploit has bee…

📅 Published: Nov. 20, 2025, 1:32 a.m. 🔄 Last Modified: Jan. 8, 2026, 4:43 p.m.

6.3

CVSS4.0

CVE-2025-13435 - Dreampie Resty HttpClient HttpClient.java request path traversal

A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the component HttpClient Module. Such manipulation of the argument filename leads to path traversal.…

📅 Published: Nov. 20, 2025, 1:32 a.m. 🔄 Last Modified: Dec. 11, 2025, 6:59 p.m.

6.9

CVSS4.0

CVE-2025-13434 - jameschz Hush Framework HTTP Host Header Util.php http headers for scripting syntax

A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file Hush\hush-lib\hush\Util.php of the component HTTP Host Header Handler. This manipulation of the argument $_SERVER['HOST'] causes improper neutralization of http headers for scripti…

📅 Published: Nov. 20, 2025, 1:02 a.m. 🔄 Last Modified: Dec. 11, 2025, 7:06 p.m.

7.3

CVSS4.0

CVE-2025-13433 - Muse Group MuseHub Windows Service Muse.Updater.exe unquoted search path

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows Service. The manipulation results in unquoted search path. …

📅 Published: Nov. 20, 2025, 12:32 a.m. 🔄 Last Modified: Nov. 24, 2025, 9:11 a.m.

5.1

CVSS4.0

CVE-2025-13424 - Campcodes Supplier Management System add_product.php sql injection

A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to t…

📅 Published: Nov. 20, 2025, 12:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:35 a.m.

4.3

CVSS3.1

CVE-2025-65222 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 21, 2025, 5:25 p.m.

7.5

CVSS3.1

CVE-2025-63889 -

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 25, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-60796 -

phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or sanitization in multiple locations including sequences.php, indexes.php, admin.p…

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 25, 2025, 7:15 p.m.

6.1

CVSS3.1

CVE-2025-60799 -

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper validation or access …

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 25, 2025, 7:08 p.m.

4.3

CVSS3.1

CVE-2025-65221 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 21, 2025, 5:25 p.m.
Total resulsts: 342311
Page 2268 of 34,232
« previous page » next page
Filters