6.1

CVSS3.1

CVE-2025-61457 -

code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-61220 -

The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauthorized access to their personal information.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-56799 -

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:46 p.m.

5

CVSS3.1

CVE-2025-62763 -

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 4:15 p.m.

8.8

CVSS3.1

CVE-2025-52079 -

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 7 p.m.

6.1

CVSS3.1

CVE-2025-60932 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Descri…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:12 p.m.

8.6

CVSS3.1

CVE-2025-60344 -

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as β€œ../”). Successful exploitation may allow access to files outside of the i…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Feb. 27, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-60772 -

Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate privileges and lock out the legitimate administrator via crafted HTTP requests.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

5.1

CVSS3.1

CVE-2025-56802 -

The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is th…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 4:04 p.m.

5.4

CVSS3.1

CVE-2025-60506 -

Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) can inject arbitrary JavaScript payloads into a comment. When any other user (Student, Teacher, or Admin) views the annotate…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:12 p.m.
Total resulsts: 343921
Page 2836 of 34,393
Β« previous page Β» next page
Filters