5.4

CVSS3.1

CVE-2025-63291 -

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying par…

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 2:52 p.m.

6.1

CVSS3.1

CVE-2024-44635 -

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:22 p.m.

3.8

CVSS3.1

CVE-2025-54560 -

A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:48 p.m.

7.6

CVSS3.1

CVE-2025-54346 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:59 p.m.

7.5

CVSS3.1

CVE-2025-63891 -

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:55 p.m.

6.5

CVSS3.1

CVE-2024-44632 -

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:37 p.m.

6.5

CVSS3.1

CVE-2024-44636 -

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:22 p.m.

6.5

CVSS3.1

CVE-2024-44639 -

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:21 p.m.

6

CVSS3.1

CVE-2025-63724 -

SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 5:42 p.m.

10

CVSS3.1

CVE-2025-54339 -

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:30 p.m.
Total resulsts: 349182
Page 3013 of 34,919
Β« previous page Β» next page
Filters