6.9

CVSS4.0

CVE-2025-13163 - Digiwin|EasyFlow GP - Insufficiently Protected Credentials

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend.

📅 Published: Nov. 17, 2025, 6:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13266 - wwwlike vlife VLifeApi SysFileApi.java create path traversal

A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/cn/wwwlike/sys/api/SysFileApi.java of the component VLifeApi. Such manipulation of the argument fileName leads to path traversal. It is possible to la…

📅 Published: Nov. 17, 2025, 6:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2025-9501 - W3 Total Cache < 2.8.13 - Unauthenticated Command Injection

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

📅 Published: Nov. 17, 2025, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-60022 -

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on and/or tamper with an encrypted communication.

📅 Published: Nov. 17, 2025, 5:51 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13265 - lsfusion platform ZipUtils.java unpackFile path traversal

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traversal. It is possible to initiate the attack r…

📅 Published: Nov. 17, 2025, 5:32 a.m. 🔄 Last Modified: Dec. 1, 2025, 3:33 p.m.

5.3

CVSS4.0

CVE-2025-13264 - SourceCodester Online Magazine Management System view_magazine.php sql injection

A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the publi…

📅 Published: Nov. 17, 2025, 5:02 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:15 p.m.

5.3

CVSS4.0

CVE-2025-13263 - SourceCodester Online Magazine Management System categories.php sql injection

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack is possible to be carried out remotely. The exploit is publ…

📅 Published: Nov. 17, 2025, 4:32 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:15 p.m.

6.9

CVSS4.0

CVE-2025-13262 - lsfusion platform UploadFileRequestHandler.java UploadFileRequestHandler path traversal

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to pa…

📅 Published: Nov. 17, 2025, 4:02 a.m. 🔄 Last Modified: Dec. 1, 2025, 3:31 p.m.

9.3

CVSS4.0

CVE-2025-13284 - ThinPLUS|ThinPLUS - OS Command Injection

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

📅 Published: Nov. 17, 2025, 3:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13261 - lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploit…

📅 Published: Nov. 17, 2025, 3:32 a.m. 🔄 Last Modified: Dec. 1, 2025, 3:30 p.m.
Total resulsts: 349182
Page 2995 of 34,919
« previous page » next page
Filters