8.1

CVSS3.1

CVE-2025-64685 -

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.5

CVSS3.1

CVE-2025-64684 -

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 4:04 p.m.

5.3

CVSS3.1

CVE-2025-64683 -

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 4:09 p.m.

2.7

CVSS3.1

CVE-2025-64682 -

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 7:53 p.m.

2.7

CVSS3.1

CVE-2025-64681 -

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 7:54 p.m.

5.3

CVSS4.0

CVE-2025-12939 - SourceCodester Interview Management System addCandidate.php sql injection

A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has b…

πŸ“… Published: Nov. 10, 2025, 1:02 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:41 p.m.

6.9

CVSS4.0

CVE-2025-12938 - projectworlds Online Admission System process_login.php sql injection

A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The attack can be initiated remotely. The exploit is publicly ava…

πŸ“… Published: Nov. 10, 2025, 12:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:26 a.m.

5.1

CVSS4.0

CVE-2025-41001 - Cross-Site Scripting (XSS) in SOPlanning

Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options.php'. This vulnerability could allow a remote us…

πŸ“… Published: Nov. 10, 2025, 9:57 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:17 p.m.

7.7

CVSS4.0

CVE-2025-12405 - Unauthorized access through stored credentials in Looker Studio

An improper privilege management vulnerability was found in Looker Studio.Β It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached…

πŸ“… Published: Nov. 10, 2025, 9:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-41107 - Stored XSS in Smart School

Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to sen…

πŸ“… Published: Nov. 10, 2025, 9:09 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 5:59 p.m.
Total resulsts: 347946
Page 2968 of 34,795
Β« previous page Β» next page
Filters