6.1

CVSS3.1

CVE-2025-64027 -

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify th…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2025-63807 -

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authen…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 4:59 p.m.

6.1

CVSS3.1

CVE-2025-60799 -

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper validation or access …

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:08 p.m.

6.5

CVSS3.1

CVE-2025-60798 -

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper sanitization. An authenticated attacker can exploit this vulnerability to execute…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:11 p.m.

6.1

CVSS3.1

CVE-2025-60796 -

phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or sanitization in multiple locations including sequences.php, indexes.php, admin.p…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2025-25613 -

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were transmitted in cleartext using…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 8:08 p.m.

6.5

CVSS3.1

CVE-2025-60797 -

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authent…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:13 p.m.

4.3

CVSS3.1

CVE-2025-65221 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:25 p.m.

9.8

CVSS3.1

CVE-2025-52410 -

Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 3:29 p.m.

7.5

CVSS3.1

CVE-2025-61138 -

Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 10, 2025, 8:45 p.m.
Total resulsts: 349182
Page 2955 of 34,919
Β« previous page Β» next page
Filters