6.5

CVSS3.1

CVE-2025-65380 -

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 7:01 p.m.

6.8

CVSS3.1

CVE-2025-59705 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 7:39 p.m.

9.8

CVSS3.1

CVE-2025-65656 -

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 6:07 p.m.

3.2

CVSS3.1

CVE-2025-59696 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase tamper events via the Chassis management board.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 7:31 p.m.

4.1

CVSS3.1

CVE-2025-59701 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted).

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 7:40 p.m.

6.8

CVSS3.1

CVE-2025-59699 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 7:41 p.m.

9.8

CVSS3.1

CVE-2025-65896 -

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 19, 2025, 6:23 p.m.

5.8

CVSS3.1

CVE-2025-59700 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection).

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:15 p.m.

6.1

CVSS3.1

CVE-2025-65186 -

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 4:48 p.m.

7.8

CVSS3.1

CVE-2025-59704 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:15 p.m.
Total resulsts: 343924
Page 2336 of 34,393
ยซ previous page ยป next page
Filters