8.8

CVSS3.1

CVE-2025-8693 -

A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

📅 Published: Nov. 18, 2025, 1:25 a.m. 🔄 Last Modified: Feb. 26, 2026, 4:56 p.m.

5.3

CVSS3.1

CVE-2025-6599 -

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt…

📅 Published: Nov. 18, 2025, 1:19 a.m. 🔄 Last Modified: Dec. 16, 2025, 9:19 p.m.

3.2

CVSS3.1

CVE-2025-12792 -

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.

📅 Published: Nov. 18, 2025, 12:18 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13325 - itsourcecode Student Information System enrollment_edit1.php sql injection

A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicl…

📅 Published: Nov. 18, 2025, 12:02 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:01 p.m.

6.9

CVSS4.0

CVE-2025-13323 - code-projects Simple Pizza Ordering System listorder.php sql injection

A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public a…

📅 Published: Nov. 18, 2025, 12:02 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:01 p.m.

9.8

CVSS3.1

CVE-2025-63695 -

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

📅 Published: Nov. 18, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 7:04 p.m.

4.8

CVSS3.1

CVE-2025-61661 - Grub2: grub2: out-of-bounds write via malicious usb device

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a malicious…

📅 Published: Nov. 18, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-64076 - cbor2: cbor2: Integer Underflow and Memory Leak leading to Denial of Service

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorrect variable reference and missing state reset in the chunk pro…

📅 Published: Nov. 18, 2025, midnight 🔄 Last Modified: Dec. 31, 2025, 2:02 a.m.

7.5

CVSS3.1

CVE-2025-63955 -

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of …

📅 Published: Nov. 18, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 5:27 p.m.

5.4

CVSS3.1

CVE-2025-63883 -

A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacent…

📅 Published: Nov. 18, 2025, midnight 🔄 Last Modified: Feb. 4, 2026, 8:42 p.m.
Total resulsts: 349182
Page 2983 of 34,919
« previous page » next page
Filters