6.1

CVSS3.1

CVE-2025-63529 -

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.

7.5

CVSS3.1

CVE-2025-65838 -

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:09 p.m.

9.1

CVSS3.1

CVE-2025-65836 -

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:09 p.m.

5.4

CVSS3.1

CVE-2025-65621 -

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:58 p.m.

9.6

CVSS3.1

CVE-2025-63535 -

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authen…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 10 p.m.

4.6

CVSS3.1

CVE-2025-63522 -

Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 3:06 a.m.

6.5

CVSS3.1

CVE-2025-65405 -

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:48 p.m.

8.1

CVSS3.1

CVE-2024-39148 -

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called β€˜magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:55 p.m.

8.8

CVSS3.1

CVE-2025-65840 -

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:58 p.m.

5.4

CVSS3.1

CVE-2025-65622 -

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 6:58 p.m.
Total resulsts: 349182
Page 2873 of 34,919
Β« previous page Β» next page
Filters