6.1

CVSS3.1

CVE-2025-60933 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Descrip…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 10:13 a.m.

4.3

CVSS3.1

CVE-2025-60511 -

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's block (e.g., administra…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:12 p.m.

6.1

CVSS3.1

CVE-2025-61255 -

Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 12:29 p.m.

7.2

CVSS3.1

CVE-2025-60500 -

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a we…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:46 p.m.

5.3

CVSS3.1

CVE-2025-59438 -

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-60751 -

GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 1:15 a.m.

6.5

CVSS3.1

CVE-2025-60790 -

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 8:08 p.m.

6.5

CVSS3.1

CVE-2025-61181 -

daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

6.5

CVSS3.1

CVE-2025-61194 -

daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:17 p.m.

6.1

CVSS3.1

CVE-2025-61457 -

code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.
Total resulsts: 343920
Page 2835 of 34,392
Β« previous page Β» next page
Filters