5.3

CVSS3.1

CVE-2025-67897 - Sequoia: Sequoia: Application crash via crafted encrypted message

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

πŸ“… Published: Dec. 14, 2025, 4:35 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:29 p.m.

7.5

CVSS3.1

CVE-2025-13126 - wpForo Forum <= 2.4.12 - Unauthenticated SQL Injection

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m…

πŸ“… Published: Dec. 14, 2025, 4:20 a.m. πŸ”„ Last Modified: April 21, 2026, 1 a.m.

7

CVSS3.1

CVE-2025-67896 - exim: Exim: Remote heap corruption vulnerability

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

πŸ“… Published: Dec. 14, 2025, 4 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-14644 - itsourcecode Student Management System update_subject.php sql injection

A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclose…

πŸ“… Published: Dec. 14, 2025, 3:32 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:18 a.m.

6.9

CVSS4.0

CVE-2025-14643 - code-projects Simple Attendance Record System check.php sql injection

A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of the argument student results in sql injection. Remote exploitation of the attack is possible. The exploit has been made publ…

πŸ“… Published: Dec. 14, 2025, 3:02 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:19 a.m.

5.1

CVSS4.0

CVE-2025-14642 - code-projects Computer Laboratory System technical_staff_pic.php unrestricted upload

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the publi…

πŸ“… Published: Dec. 14, 2025, 2:32 a.m. πŸ”„ Last Modified: Dec. 16, 2025, 8:07 p.m.

5.1

CVSS4.0

CVE-2025-14641 - code-projects Computer Laboratory System admin_pic.php unrestricted upload

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Dec. 14, 2025, 2:02 a.m. πŸ”„ Last Modified: Dec. 16, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-14640 - code-projects Student File Management System save_student.php sql injection

A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation of the argument stud_no can lead to sql injection. The attack may be launched remotely. The exploit has been published a…

πŸ“… Published: Dec. 14, 2025, 1:32 a.m. πŸ”„ Last Modified: Dec. 16, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-14639 - itsourcecode Student Management System uprec.php sql injection

A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: Dec. 14, 2025, 1:02 a.m. πŸ”„ Last Modified: Dec. 16, 2025, 7:54 p.m.

6.9

CVSS4.0

CVE-2025-14638 - itsourcecode Online Pet Shop Management System update_cnp.php sql injection

A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been discl…

πŸ“… Published: Dec. 14, 2025, 12:32 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:23 a.m.
Total resulsts: 348618
Page 2561 of 34,862
Β« previous page Β» next page
Filters