8.7

CVSS4.0

CVE-2025-12864 - e-Excellence|U-Office Force - SQL Injection

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.

πŸ“… Published: Nov. 10, 2025, 2:15 a.m. πŸ”„ Last Modified: Nov. 18, 2025, 6:04 p.m.

5.3

CVSS4.0

CVE-2025-12926 - SourceCodester Farm Management System review.php sql injection

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the pub…

πŸ“… Published: Nov. 10, 2025, 2:02 a.m. πŸ”„ Last Modified: Nov. 18, 2025, 6:03 p.m.

6.9

CVSS4.0

CVE-2025-12925 - rymcu forest UserDicController.java deleteDic authorization

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack …

πŸ“… Published: Nov. 10, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-12924 - rymcu forest BankController.java GlobalResult authorization

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack may be initiated remot…

πŸ“… Published: Nov. 10, 2025, 1:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.1

CVSS4.0

CVE-2025-12923 - liweiyi ChestnutCMS download resourceDownload path traversal

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publicl…

πŸ“… Published: Nov. 10, 2025, 12:32 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:31 p.m.

5.3

CVSS4.0

CVE-2025-12922 - OpenClinica Community Edition CRF Data Import ImportCRFData path traversal

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be initiated remotely. Th…

πŸ“… Published: Nov. 10, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 4:02 p.m.

6.5

CVSS3.1

CVE-2025-63617 -

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:10 p.m.

4.5

CVSS3.1

CVE-2025-63712 -

Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF prot…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-63709 -

A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered in the browser of a…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2025-63149 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:08 p.m.
Total resulsts: 347988
Page 2975 of 34,799
Β« previous page Β» next page
Filters