5.3

CVSS4.0

CVE-2025-9438 - 1000projects Online Project Report Submission and Evaluation System add_student.php cross site scri…

A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of the file /admin/add_student.php. The manipulation of the argument address results in cross site scripting. The attack can be executed remotely. The expl…

πŸ“… Published: Aug. 26, 2025, 1:32 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 1:32 a.m.

5.3

CVSS4.0

CVE-2025-9434 - 1000projects Online Project Report Submission and Evaluation System edit_title.php cross site scrip…

A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the file /admin/edit_title.php?id=1. Executing manipulation of the argument desc can lead to cross site scripting. The attack may be launched remotely. The …

πŸ“… Published: Aug. 26, 2025, 1:02 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 1:02 a.m.

5.3

CVSS4.0

CVE-2025-9433 - mtons mblog Admin Panel list cross site scripting

A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made …

πŸ“… Published: Aug. 26, 2025, 1:02 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 1:02 a.m.

5.3

CVSS4.0

CVE-2025-9432 - mtons mblog Admin Panel list cross site scripting

A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclose…

πŸ“… Published: Aug. 26, 2025, 12:32 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 12:32 a.m.

5.3

CVSS4.0

CVE-2025-9431 - mtons mblog search cross site scripting

A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Aug. 26, 2025, 12:02 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 12:02 a.m.

4.8

CVSS4.0

CVE-2025-9430 - mtons mblog update cross site scripting

A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.

πŸ“… Published: Aug. 26, 2025, 12:02 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 12:02 a.m.

0.0

CVE-2025-25733 -

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the devi…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:52 p.m.

0.0

CVE-2024-39335 -

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Aug. 27, 2025, 2:18 p.m.

0.0

CVE-2025-25732 -

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to roo…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:51 p.m.

7.5

CVSS3.1

CVE-2025-52218 -

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text or limited HTML into the login page.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Aug. 27, 2025, 2:12 p.m.
Total resulsts: 307159
Page 23 of 30,716
Β« previous page Β» next page
Filters