3.8

CVSS3.1

CVE-2025-63678 -

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 5:56 p.m.

7.1

CVSS3.1

CVE-2025-63497 -

The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated atta…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 11:30 p.m.

7.5

CVSS3.1

CVE-2025-63153 -

TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:23 p.m.

5.3

CVSS4.0

CVE-2025-12921 - OpenClinica Community Edition CRF Data Import ImportCRFData xml injection

A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of the component CRF Data Import. Such manipulation of the argument xml_file leads to xml injection. It is possible to la…

πŸ“… Published: Nov. 9, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 4:12 p.m.

4.8

CVSS4.0

CVE-2025-12920 - qianfox FoxCMS Product.php edit cross site scripting

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publi…

πŸ“… Published: Nov. 9, 2025, 11:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:25 a.m.

6.3

CVSS4.0

CVE-2025-12919 - EverShop Order Order.resolvers.js resource injection

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be perf…

πŸ“… Published: Nov. 9, 2025, 8:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:25 a.m.

2.3

CVSS4.0

CVE-2025-12918 - yungifez Skuul School Management System View Fee Invoice fee-invoices resource injection

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /dashboard/fees/fee-invoices/ of the component View Fee Invoice. Performing manipulation of the argument invoice_id results in improper control of reso…

πŸ“… Published: Nov. 9, 2025, 8:02 a.m. πŸ”„ Last Modified: Dec. 11, 2025, 11:36 p.m.

5.3

CVSS4.0

CVE-2025-12917 - TOZED ZLT T10 Reboot proc_post denial of service

A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. Such manipulation leads to denial of service. Access to the local network is required for this attack to succeed. The exploit …

πŸ“… Published: Nov. 9, 2025, 7:32 a.m. πŸ”„ Last Modified: Dec. 10, 2025, 5:52 p.m.

5.5

CVSS3.1

CVE-2025-40109 - crypto: rng - Ensure set_ent is always present

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since only drbg provides it.

πŸ“… Published: Nov. 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-40108 - serial: qcom-geni: Fix blocked task

In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: Fix blocked task Revert commit 1afa70632c39 ("serial: qcom-geni: Enable PM runtime for serial driver") and its dependent commit 86fa39dd6fb7 ("serial: qcom-geni: Enable Serial on SA8255p Qualcomm platforms") be…

πŸ“… Published: Nov. 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3097 of 34,919
Β« previous page Β» next page
Filters