5.5

CVSS3.1

CVE-2023-53767 - wifi: ath12k: fix memory leak in ath12k_qmi_driver_event_work()

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_qmi_driver_event_work() Currently the buffer pointed by event is not freed in case ATH12K_FLAG_UNREGISTERING bit is set, this causes memory leak. Add a goto skip instead of return, to ensu…

📅 Published: Dec. 8, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-67043 -

DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-67038. Reason: This record is a reservation duplicate of CVE-2025-67038. Notes: All CVE users should reference CVE-2025-67038 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

📅 Published: Dec. 8, 2025, midnight 🔄 Last Modified: Dec. 19, 2025, 3:59 p.m.

0.0

CVE-2025-67045 -

DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-67041. Reason: This record is a reservation duplicate of CVE-2025-67041. Notes: All CVE users should reference CVE-2025-67041 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

📅 Published: Dec. 8, 2025, midnight 🔄 Last Modified: Dec. 19, 2025, 3:58 p.m.

4.8

CVSS4.0

CVE-2025-14205 - code-projects Chamber of Commerce Membership Management System Your Info membership_profile.php cro…

A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /membership_profile.php of the component Your Info Handler. Performing manipulation of the argument Full Name/Address/City/State results in cross site scripti…

📅 Published: Dec. 7, 2025, 11:32 p.m. 🔄 Last Modified: Dec. 10, 2025, 5:47 p.m.

5.3

CVSS4.0

CVE-2025-14204 - TykoDev cherry-studio-TykoFork OAuth Server Discovery oauth-authorization-server redirectToAuthoriz…

A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-known/oauth-authorization-server of the component OAuth Server Discovery. Such manipulation of the argument authorizationUrl leads to os command injection…

📅 Published: Dec. 7, 2025, 11:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-14203 - code-projects Question Paper Generator selectquestionuser.php sql injection

A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.php. This manipulation of the argument subid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may…

📅 Published: Dec. 7, 2025, 9:32 p.m. 🔄 Last Modified: Dec. 10, 2025, 5:48 p.m.

4.8

CVSS4.0

CVE-2025-14201 - alokjaiswal Hotel-Management-services-using-MYSQL-and-php dishsub.php cross site scripting

A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It …

📅 Published: Dec. 7, 2025, 6:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 5:43 a.m.

5.1

CVSS4.0

CVE-2025-14200 - alokjaiswal Hotel-Management-services-using-MYSQL-and-php Request Pending usersub.php cross site sc…

A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible …

📅 Published: Dec. 7, 2025, 5:32 p.m. 🔄 Last Modified: Feb. 24, 2026, 5:42 a.m.

5.3

CVSS4.0

CVE-2025-14199 - Verysync 微力同步 Web Administration text.txt unrestricted upload

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration Module. Executing manipulation can lead to unrestricted upload. The attack may be performed from r…

📅 Published: Dec. 7, 2025, 5:02 p.m. 🔄 Last Modified: Dec. 11, 2025, 6:07 p.m.

6.9

CVSS4.0

CVE-2025-14198 - Verysync 微力同步 Web Administration download information disclosure

A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummytoken of the component Web Administration Module. Performing manipulation results in information disclosure. The attack is possible to be carried out remot…

📅 Published: Dec. 7, 2025, 4:32 p.m. 🔄 Last Modified: Dec. 11, 2025, 6:08 p.m.
Total resulsts: 349182
Page 2792 of 34,919
« previous page » next page
Filters