6.9

CVSS4.0

CVE-2025-14578 - itsourcecode Student Management System update_account.php sql injection

A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /update_account.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available tโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.7

CVSS4.0

CVE-2024-58314 - Atcom 2.7.x.x Authenticated Command Injection via Web Configuration CGI

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remotโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:57 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.7

CVSS4.0

CVE-2024-58311 - Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation oโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:57 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.6

CVSS4.0

CVE-2024-58305 - WonderCMS 4.3.2 Cross-Site Scripting Remote Code Execution via Module Installation

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticateโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

9.3

CVSS4.0

CVE-2024-58299 - PCMan FTP Server 2.0 Remote Buffer Overflow via 'pwd' Command

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

๐Ÿ“… Published: Dec. 12, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.5

CVSS4.0

CVE-2024-14010 - Typora 1.7.4 OS Command Injection via Export PDF Preferences

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

๐Ÿ“… Published: Dec. 12, 2025, 7:55 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

5.1

CVSS4.0

CVE-2025-67734 - Frappe Authenticated Users can Execute JavaScript through its Job Form

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed iโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:48 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.7

CVSS4.0

CVE-2025-14572 - UTT ่ฟ›ๅ– 512W formWebAuthGlobalConfig memory corruption

A vulnerability was found in UTT ่ฟ›ๅ– 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAuthGlobalConfig. Performing manipulation of the argument hidcontact results in memory corruption. Remote exploitation of the attack is possible. The exploit has been made public andโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

8.6

CVSS3.1

CVE-2025-8083 - Vuetify Prototype Pollution via Preset options

The Preset configuration https://v2.vuetifyjs.com/en/features/presets ย feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html ย due to the internal 'mergeDeep' utility function used to merge options witโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:29 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-14373 -

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: Dec. 12, 2025, 7:20 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 9:15 p.m.
Total resulsts: 322292
Page 23 of 32,230
ยซ previous page ยป next page
Filters