7.8

CVSS4.0

CVE-2025-58464 - QuMagie

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QuMagie 2.7.3 and later

πŸ“… Published: Nov. 7, 2025, 3:10 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:10 p.m.

2.2

CVSS4.0

CVE-2025-58465 - Download Station

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Dow…

πŸ“… Published: Nov. 7, 2025, 3:09 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:09 p.m.

1.2

CVSS4.0

CVE-2025-58469 - QuLog Center

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) …

πŸ“… Published: Nov. 7, 2025, 3:08 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:08 p.m.

5.1

CVSS4.0

CVE-2025-12860 - DedeBIZ freelist_main.php sql injection

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

πŸ“… Published: Nov. 7, 2025, 3:02 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

5.1

CVSS4.0

CVE-2025-12859 - DedeBIZ templets_one_edit.php sql injection

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Nov. 7, 2025, 3:02 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:15 p.m.

5.1

CVSS4.0

CVE-2025-12857 - code-projects Responsive Hotel Site roombook.php sql injection

A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation of the argument rid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publi…

πŸ“… Published: Nov. 7, 2025, 2:02 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:02 p.m.

9.3

CVSS4.0

CVE-2025-34299 - Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

πŸ“… Published: Nov. 7, 2025, 1:51 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:51 p.m.

5.1

CVSS4.0

CVE-2025-12856 - code-projects Responsive Hotel Site reservation.php sql injection

A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and co…

πŸ“… Published: Nov. 7, 2025, 1:32 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 5:19 p.m.

5.1

CVSS4.0

CVE-2025-12855 - code-projects Responsive Hotel Site newsletterdel.php sql injection

A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of the argument eid results in sql injection. It is possible to launch the attack remotely. The exploit has been released…

πŸ“… Published: Nov. 7, 2025, 1:32 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 3:57 p.m.

8.8

CVSS3.1

CVE-2025-10968 - SQLi in GG Soft's PaperWork

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection.This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.

πŸ“… Published: Nov. 7, 2025, 1:08 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:08 p.m.
Total resulsts: 317340
Page 3 of 31,734
Β« previous page Β» next page
Filters