7.5

CVSS3.1

CVE-2025-65073 - openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signat…

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-63748 -

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, wh…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 3:49 p.m.

6.1

CVSS3.1

CVE-2025-64046 -

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:11 p.m.

6.5

CVSS3.1

CVE-2024-44644 -

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:11 p.m.

6.5

CVSS3.1

CVE-2024-44662 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:45 p.m.

8.1

CVSS3.1

CVE-2025-63916 -

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing them to cmd.exe, allowing attackers to execute arbitrary system commands with the privileges of the user runn…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:23 p.m.

3.5

CVSS3.1

CVE-2025-63292 -

Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 RΓ©volution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM …

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 8:50 p.m.

6.5

CVSS3.1

CVE-2024-44641 -

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:11 p.m.

6.1

CVSS3.1

CVE-2024-46334 -

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.

4.6

CVSS3.1

CVE-2024-46335 -

PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:09 p.m.
Total resulsts: 349182
Page 2997 of 34,919
Β« previous page Β» next page
Filters