8.1

CVSS3.1

CVE-2025-57489 -

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 7:26 p.m.

9.8

CVSS3.1

CVE-2025-51683 -

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 6:16 p.m.

8.4

CVSS3.1

CVE-2025-61229 -

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 4:15 p.m.

7.8

CVSS3.1

CVE-2025-61228 -

An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 7:45 p.m.

6.8

CVSS3.1

CVE-2024-32384 -

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

πŸ“… Published: Dec. 1, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 3:50 p.m.

5.3

CVSS4.0

CVE-2025-13796 - deco-cx apps Parameter analyticsScript.ts AnalyticsScript server-side request forgery

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation of the argument url leads to server-side request forgery. The…

πŸ“… Published: Nov. 30, 2025, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-13795 - codingWithElias School Management System Edit Student Info student-view.php cross site scripting

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting.…

πŸ“… Published: Nov. 30, 2025, 11:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-35028 - HexStrike AI MCP Server Command Injection

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There i…

πŸ“… Published: Nov. 30, 2025, 9:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13793 - winston-dsouza Ecommerce-Website GET Parameter header_menu.php cross site scripting

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead…

πŸ“… Published: Nov. 30, 2025, 5:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13792 - Qualitor getResumo.php eval code injection

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in code injection. Remote exploitation of the attack i…

πŸ“… Published: Nov. 30, 2025, 4:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2876 of 34,919
Β« previous page Β» next page
Filters