6.5

CVSS3.1

CVE-2025-65406 -

A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:45 p.m.

6.5

CVSS3.1

CVE-2025-65404 -

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:51 p.m.

6.5

CVSS3.1

CVE-2025-65403 -

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 9:50 p.m.

5.4

CVSS3.1

CVE-2025-64030 -

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScrip…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 29, 2025, 3:01 p.m.

8.5

CVSS3.1

CVE-2025-63534 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg and e…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 10 p.m.

8.5

CVSS3.1

CVE-2025-63533 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript p…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:07 p.m.

9.6

CVSS3.1

CVE-2025-63532 -

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass au…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:08 p.m.

8.5

CVSS3.1

CVE-2025-63528 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the erro…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.

8.5

CVSS3.1

CVE-2025-63527 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript p…

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.

8.5

CVSS3.1

CVE-2025-63526 -

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg parameter, …

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.
Total resulsts: 349182
Page 2874 of 34,919
Β« previous page Β» next page
Filters