6.9

CVSS4.0

CVE-2025-15420 - Yonyou KSOA agent_work_report.jsp sql injection

A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The veโ€ฆ

๐Ÿ“… Published: Jan. 2, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 8:05 a.m.

4.8

CVSS4.0

CVE-2025-15419 - Open5GS GTPv2-C Flow s5c-handler.c sgwc_s5c_handle_create_session_response denial of service

A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c of the component GTPv2-C Flow Handler. Executing a manipulation can lead to denial of service. The attack needs to be launched locโ€ฆ

๐Ÿ“… Published: Jan. 2, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

6.1

CVSS3.1

CVE-2025-45286 -

A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 7, 2026, 5:25 p.m.

5.3

CVSS3.1

CVE-2024-55374 -

REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 3:27 p.m.

7.5

CVSS3.1

CVE-2025-67158 -

An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive information and escalate privileges via a crafted HTTP request.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:44 a.m.

9.8

CVSS3.1

CVE-2025-67268 - gpsd: gpsd: Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyviewโ€ฆ

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 3:33 p.m.

7.5

CVSS3.1

CVE-2025-67269 - gpsd: gpsd: Denial of Service due to malformed NAVCOM packet parsing

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without checking if the input โ€ฆ

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 9, 2026, 10:07 p.m.

7.5

CVSS3.1

CVE-2025-67160 -

An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:44 a.m.

9.8

CVSS3.1

CVE-2025-65125 -

SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-67159 -

Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.

๐Ÿ“… Published: Jan. 2, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:44 a.m.
Total resulsts: 349182
Page 2310 of 34,919
ยซ previous page ยป next page
Filters