6.1

CVSS3.1

CVE-2025-63830 -

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 1:20 p.m.

5.4

CVSS3.1

CVE-2025-64084 -

An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL comma…

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:50 p.m.

3.7

CVSS3.1

CVE-2025-54559 -

An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:52 p.m.

9.6

CVSS3.1

CVE-2025-54343 -

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:27 p.m.

6.5

CVSS3.1

CVE-2025-54348 -

A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:54 p.m.

6.5

CVSS3.1

CVE-2024-55016 -

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:20 p.m.

4.3

CVSS3.1

CVE-2025-54562 -

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:40 p.m.

6.5

CVSS3.1

CVE-2024-44630 -

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, st…

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:40 p.m.

5.5

CVSS3.1

CVE-2025-63745 -

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 7:01 p.m.

4.3

CVSS3.1

CVE-2025-54561 -

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema.

πŸ“… Published: Nov. 14, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 2:46 p.m.
Total resulsts: 349182
Page 3015 of 34,919
Β« previous page Β» next page
Filters