6.2

CVSS3.1

CVE-2025-10023 - A user with elevated privileges can inject XSS in the Services Meta-services configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.9, from 24.04.…

📅 Published: Oct. 27, 2025, 3:07 p.m. 🔄 Last Modified: Jan. 26, 2026, 2:02 p.m.

6.8

CVSS3.1

CVE-2025-12351 - Inadequate access control measure allows unauthorized users to access restricted administrative fun…

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of t…

📅 Published: Oct. 27, 2025, 3:03 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.3

CVSS4.0

CVE-2025-12290 - Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 359 cross s…

A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to …

📅 Published: Oct. 27, 2025, 3:02 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.3

CVSS4.0

CVE-2025-12289 - Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1001 cross …

A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to…

📅 Published: Oct. 27, 2025, 3:02 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.4

CVSS3.1

CVE-2025-36121 - HTML Injection Vulnerability in a Specific URL Endpoint of the IBM OpenPages Application

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

📅 Published: Oct. 27, 2025, 2:56 p.m. 🔄 Last Modified: Nov. 3, 2025, 5:26 p.m.

0

CVSS4.0

CVE-2025-26862 - PingFederate unexpected browser flow initiation in redirectless mode

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

📅 Published: Oct. 27, 2025, 2:39 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

9.4

CVSS4.0

CVE-2025-34292 - BeWelcome/Rox PHP Object Injection RCE

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in \\RoxPostHandler::getCallbackAction and the 'memory cookie' re…

📅 Published: Oct. 27, 2025, 2:36 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

5.3

CVSS4.0

CVE-2025-12288 - Bdtask Pharmacy Management System User Profile edit_user authorization

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now…

📅 Published: Oct. 27, 2025, 2:32 p.m. 🔄 Last Modified: Nov. 24, 2025, 12:16 p.m.

5.1

CVSS4.0

CVE-2025-12287 - Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may …

📅 Published: Oct. 27, 2025, 2:32 p.m. 🔄 Last Modified: Jan. 7, 2026, 5:06 p.m.

7.3

CVSS4.0

CVE-2025-12286 - VeePN AVService avservice.exe unquoted search path

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of complexity is needed f…

📅 Published: Oct. 27, 2025, 2:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 8:16 a.m.
Total resulsts: 344111
Page 2752 of 34,412
« previous page » next page
Filters