6.5

CVSS3.1

CVE-2024-44660 -

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:45 p.m.

6.5

CVSS3.1

CVE-2024-44651 -

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:09 p.m.

7.1

CVSS3.1

CVE-2025-63917 -

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exf…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:27 p.m.

6.1

CVSS3.1

CVE-2024-46336 -

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.

6.2

CVSS3.1

CVE-2025-63918 -

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:18 p.m.

3.2

CVSS3.1

CVE-2025-65083 -

GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects an arbitrary proxy server without consideration of whether outbound HTTPS connections from the proxy server to Internet servers succeed …

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-63708 -

Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability occurs in the webfonts API handling mechanism where font family names are not properly sanit…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 8:27 p.m.

9.8

CVSS3.1

CVE-2025-63747 -

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain…

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 3:50 p.m.

6.5

CVSS3.1

CVE-2024-44658 -

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:46 p.m.

6.5

CVSS3.1

CVE-2024-44652 -

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

πŸ“… Published: Nov. 17, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:10 p.m.
Total resulsts: 349182
Page 2999 of 34,919
Β« previous page Β» next page
Filters