9.6

CVSS3.1

CVE-2025-63525 -

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:15 p.m.

6.5

CVSS3.1

CVE-2025-63523 -

FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 3:06 a.m.

5.4

CVSS3.1

CVE-2025-63317 -

Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 6:11 p.m.

9.8

CVSS3.1

CVE-2025-51682 -

mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative features. Additionally, they can craft requests based on the client-side code to call these administrative functions directly.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 6:21 p.m.

7.5

CVSS3.1

CVE-2024-56089 -

An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake responses by reviving the birthday attack.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 3:59 p.m.

6.1

CVSS3.1

CVE-2025-63520 -

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 11:59 a.m.

7.1

CVSS3.1

CVE-2025-63365 -

SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file processing component, specifically in the functionality responsible for extracting and handling EPUB archive contents.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 1:17 p.m.

5.3

CVSS3.1

CVE-2024-32388 -

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and access UDP-based services that would otherwise be protected.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 1:57 p.m.

6.5

CVSS3.1

CVE-2025-65408 -

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 1:43 p.m.

10

CVSS3.1

CVE-2025-63531 -

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an โ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 12:15 p.m.
Total resulsts: 349182
Page 2875 of 34,919
ยซ previous page ยป next page
Filters