9.3

CVSS4.0

CVE-2025-12866 - Hundred Plus๏ฝœEIP Plus - Weak Password Recovery Mechanism

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

๐Ÿ“… Published: Nov. 10, 2025, 2:45 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-12927 - DedeBIZ archives_add.php sql injection

A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may โ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:26 a.m.

8.7

CVSS4.0

CVE-2025-12865 - e-Excellence๏ฝœU-Office Force - SQL Injection

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.

๐Ÿ“… Published: Nov. 10, 2025, 2:19 a.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 6:04 p.m.

8.7

CVSS4.0

CVE-2025-12864 - e-Excellence๏ฝœU-Office Force - SQL Injection

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.

๐Ÿ“… Published: Nov. 10, 2025, 2:15 a.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 6:04 p.m.

5.3

CVSS4.0

CVE-2025-12926 - SourceCodester Farm Management System review.php sql injection

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the pubโ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 6:03 p.m.

6.9

CVSS4.0

CVE-2025-12925 - rymcu forest UserDicController.java deleteDic authorization

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack โ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-12924 - rymcu forest BankController.java GlobalResult authorization

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack may be initiated remotโ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.1

CVSS4.0

CVE-2025-12923 - liweiyi ChestnutCMS download resourceDownload path traversal

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publiclโ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:31 p.m.

5.3

CVSS4.0

CVE-2025-12922 - OpenClinica Community Edition CRF Data Import ImportCRFData path traversal

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be initiated remotely. Thโ€ฆ

๐Ÿ“… Published: Nov. 10, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Dec. 2, 2025, 4:02 p.m.

6.5

CVSS3.1

CVE-2025-63617 -

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

๐Ÿ“… Published: Nov. 10, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 5, 2026, 3:10 p.m.
Total resulsts: 347821
Page 2958 of 34,783
ยซ previous page ยป next page
Filters