8.8

CVSS3.1

CVE-2025-66918 -

edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2025-65472 -

A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 7:29 p.m.

8.8

CVSS3.1

CVE-2025-56118 -

OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2025-55311 -

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by …

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2025-56109 -

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Jan. 26, 2026, 8:43 p.m.

8.8

CVSS3.1

CVE-2025-56089 -

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Jan. 27, 2026, 6:05 p.m.

8.8

CVSS3.1

CVE-2025-56129 -

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 8 p.m.

7.8

CVSS3.1

CVE-2025-55312 -

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference…

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:34 p.m.

8.8

CVSS3.1

CVE-2025-56090 -

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Jan. 27, 2026, 5:38 p.m.

8.8

CVSS3.1

CVE-2025-66429 -

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 6:34 p.m.
Total resulsts: 349182
Page 2669 of 34,919
Β« previous page Β» next page
Filters