3.2

CVSS3.1

CVE-2025-55174 -

In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-65675 -

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 5, 2025, 2:12 p.m.

6.1

CVSS3.1

CVE-2025-65237 -

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 8:46 p.m.

9.8

CVSS3.1

CVE-2025-65235 -

OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 8:47 p.m.

8

CVSS3.1

CVE-2025-65202 -

TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 5, 2025, 1:34 p.m.

9.8

CVSS3.1

CVE-2025-50433 -

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 29, 2025, 3:46 p.m.

7.5

CVSS3.1

CVE-2025-65278 -

An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 30, 2025, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-63938 -

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 8:48 p.m.

4.3

CVSS3.1

CVE-2025-65670 -

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts tโ€ฆ

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2025, 8:51 p.m.

5.4

CVSS3.1

CVE-2025-65676 -

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2025, 8:50 p.m.
Total resulsts: 349182
Page 2900 of 34,919
ยซ previous page ยป next page
Filters