5

CVSS3.1

CVE-2025-12766 - Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of affected versionโ€ฆ

An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerryยฎ AtHocยฎ (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS).

๐Ÿ“… Published: Nov. 19, 2025, 4:08 p.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 5:22 p.m.

7.2

CVSS3.1

CVE-2025-65022 - i-Educar Authenticated Time-based SQL Injection in `agenda.php`

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the appliโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 5:24 p.m.

7.2

CVSS3.1

CVE-2025-65023 - i-Educar Authenticated Time-based SQL Injection in `funcionario_vinculo_cad.php`

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands โ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 5:20 p.m.

7.2

CVSS3.1

CVE-2025-65024 - i-Educar Authenticated Time-based SQL Injection in `agenda_admin_cad.php`

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands againstโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Nov. 24, 2025, 8:26 p.m.

8.6

CVSS4.0

CVE-2025-10703 -

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for Jโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 3:47 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

8.6

CVSS4.0

CVE-2025-10702 -

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for โ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 3:46 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

4.8

CVSS4.0

CVE-2025-13397 - mrubyc alloc.c mrbc_raw_realloc null pointer dereference

A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file src/alloc.c. Such manipulation of the argument ptr leads to null pointer dereference. An attack has to be approached locally. The name of the patch is 009111904807b8567262036bf4529โ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 7:58 p.m.

5.3

CVSS4.0

CVE-2025-13396 - code-projects Courier Management System add-office.php sql injection

A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public andโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 4:23 p.m.

5.4

CVSS3.1

CVE-2025-11963 - Reflected XSS in Saysis's StarCities

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities allows Reflected XSS.This issue affects StarCities: before 1.1.61.

๐Ÿ“… Published: Nov. 19, 2025, 2:03 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 9:15 a.m.

4.7

CVSS3.1

CVE-2025-0421 - iFrame Injection in Mikrogrup's Shopside

Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allows iFrame Overlay.This issue affects Shopside: through 05022025.

๐Ÿ“… Published: Nov. 19, 2025, 1:28 p.m. ๐Ÿ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.
Total resulsts: 342301
Page 2275 of 34,231
ยซ previous page ยป next page
Filters