3.5

CVSS3.1

CVE-2025-63292 -

Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 RΓ©volution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM …

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 8:50 p.m.

6.1

CVSS3.1

CVE-2024-46336 -

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.

6.5

CVSS3.1

CVE-2024-44648 -

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.

6.5

CVSS3.1

CVE-2024-44664 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:43 p.m.

6.2

CVSS3.1

CVE-2025-63918 -

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:18 p.m.

7.1

CVSS3.1

CVE-2025-63917 -

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exf…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:27 p.m.

6.5

CVSS3.1

CVE-2024-44663 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:45 p.m.

6.5

CVSS3.1

CVE-2024-44658 -

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:46 p.m.

8.8

CVSS3.1

CVE-2025-63748 -

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, wh…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 3:49 p.m.

6.5

CVSS3.1

CVE-2024-44654 -

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:47 p.m.
Total resulsts: 346536
Page 2733 of 34,654
Β« previous page Β» next page
Filters