7.1

CVSS4.0

CVE-2025-4321 - DoS in RS9116W-WiSeConnect L2CAP protocol due to reception of malformed packets

In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation

πŸ“… Published: Nov. 17, 2025, 2:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-13310 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Nov. 17, 2025, 2:49 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 2:50 p.m.

5.3

CVSS4.0

CVE-2025-13287 - itsourcecode Online Voting System index.php sql injection

A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument id/category can lead to sql injection. The attack can be executed remotely. The exploit has been made available to…

πŸ“… Published: Nov. 17, 2025, 2:32 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:12 p.m.

5.3

CVSS4.0

CVE-2025-13286 - itsourcecode Online Voting System ajax.php sql injection

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been …

πŸ“… Published: Nov. 17, 2025, 2:02 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:12 p.m.

6.9

CVSS4.0

CVE-2025-13285 - itsourcecode Online Voting System login.php sql injection

A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: Nov. 17, 2025, 1:32 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:12 p.m.

6.9

CVSS4.0

CVE-2025-13280 - CodeAstro Simple Inventory System Login index.php sql injection

A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been …

πŸ“… Published: Nov. 17, 2025, 1:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-13279 - code-projects Nero Social Networking Site profilefriends.php sql injection

A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and co…

πŸ“… Published: Nov. 17, 2025, 12:32 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:13 p.m.

5.3

CVSS4.0

CVE-2025-13278 - projectworlds Advanced Library Management System borrowed_book_search.php sql injection

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The attack can be launched remotely. The exploit has been disclose…

πŸ“… Published: Nov. 17, 2025, 12:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:32 a.m.

7.3

CVSS4.0

CVE-2025-40936 -

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This could allow an attacker to …

πŸ“… Published: Nov. 17, 2025, 11:39 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-40834 -

A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow an attacker to execute cross-site scripting attacks.

πŸ“… Published: Nov. 17, 2025, 11:39 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346551
Page 2730 of 34,656
Β« previous page Β» next page
Filters