8.1

CVSS3.1

CVE-2025-63916 -

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing them to cmd.exe, allowing attackers to execute arbitrary system commands with the privileges of the user runn…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:23 p.m.

6.1

CVSS3.1

CVE-2025-64046 -

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:11 p.m.

6.5

CVSS3.1

CVE-2024-44653 -

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:09 p.m.

6.5

CVSS3.1

CVE-2024-44641 -

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:11 p.m.

6.1

CVSS3.1

CVE-2024-46334 -

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.

5.4

CVSS3.1

CVE-2024-44661 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:44 p.m.

6.5

CVSS3.1

CVE-2024-44662 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-65073 - openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signat…

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-63747 -

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 3:50 p.m.

9.8

CVSS3.1

CVE-2024-44659 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:44 p.m.
Total resulsts: 346533
Page 2734 of 34,654
Β« previous page Β» next page
Filters