5.3

CVSS4.0

CVE-2025-15494 - RainyGao DocSys UserMapper.xml sql injection

A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public an…

📅 Published: Jan. 9, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 9, 2026, 7:16 p.m.

5.3

CVSS4.0

CVE-2025-15493 - RainyGao DocSys ReposAuthMapper.xml sql injection

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit has…

📅 Published: Jan. 9, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 9, 2026, 7:16 p.m.

7.7

CVSS4.0

CVE-2026-22196 - GestSup <= 3.2.56 SQL Injection in Ticket Creation

GestSup versions up to and including 3.2.56 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database que…

📅 Published: Jan. 9, 2026, 4:23 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

5.1

CVSS4.0

CVE-2026-22198 - GestSup <= 3.2.56 Stored XSS in API Error Logs

GestSup versions up to and including 3.2.56 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with a crafted X-API-KEY header value (for example, to /api/v1/ticket.php), an unauthenticated attacker can caus…

📅 Published: Jan. 9, 2026, 4:19 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

7.5

CVSS4.0

CVE-2026-22197 - GestSup <= 3.2.56 Multiple SQL Injections in Asset List

GestSup versions up to and including 3.2.56 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to m…

📅 Published: Jan. 9, 2026, 4:18 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

7.7

CVSS4.0

CVE-2026-22195 - GestSup <= 3.2.56 SQL Injection in Search Bar

GestSup versions up to and including 3.2.56 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitat…

📅 Published: Jan. 9, 2026, 4:18 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

8.9

CVSS4.0

CVE-2026-22194 - GestSup <= 3.2.56 CSRF Allows Privileged Actions

GestSup versions up to and including 3.2.56 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This…

📅 Published: Jan. 9, 2026, 4:17 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

10

CVSS4.0

CVE-2025-69426 - Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY all…

📅 Published: Jan. 9, 2026, 4:15 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.

6.5

CVSS3.1

CVE-2025-46645 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralizatio…

📅 Published: Jan. 9, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 10, 2026, 4:55 a.m.

10

CVSS4.0

CVE-2025-69425 - Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who ext…

📅 Published: Jan. 9, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 9, 2026, 6:37 p.m.
Total resulsts: 327160
Page 26 of 32,716
« previous page » next page
Filters