5.4

CVSS3.1

CVE-2025-65621 -

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:58 p.m.

6.8

CVSS3.1

CVE-2024-32384 -

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 3:50 p.m.

5.4

CVSS3.1

CVE-2025-64030 -

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScrip…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 29, 2025, 3:01 p.m.

6.1

CVSS3.1

CVE-2025-63529 -

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.

8.1

CVSS3.1

CVE-2025-57489 -

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 7:26 p.m.

6.5

CVSS3.1

CVE-2025-65408 -

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:43 p.m.

8.5

CVSS3.1

CVE-2025-63527 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript p…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.

6.5

CVSS3.1

CVE-2025-65404 -

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:51 p.m.

5.3

CVSS4.0

CVE-2025-13796 - deco-cx apps Parameter analyticsScript.ts AnalyticsScript server-side request forgery

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation of the argument url leads to server-side request forgery. The…

πŸ“… Published: Nov. 30, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 5:39 p.m.

4.8

CVSS4.0

CVE-2025-13795 - codingWithElias School Management System Edit Student Info student-view.php cross site scripting

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting.…

πŸ“… Published: Nov. 30, 2025, 11:02 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 5:40 p.m.
Total resulsts: 343887
Page 2348 of 34,389
Β« previous page Β» next page
Filters