7.5

CVSS3.1

CVE-2025-60574 -

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 11:39 p.m.

7.5

CVSS3.1

CVE-2025-57698 -

AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the valid…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 8:51 p.m.

6.1

CVSS3.1

CVE-2025-63640 -

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:13 p.m.

6.1

CVSS3.1

CVE-2025-63785 -

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a text element. An atta…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 4:06 p.m.

6.1

CVSS3.1

CVE-2025-63714 -

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of us…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:02 p.m.

6.1

CVSS3.1

CVE-2025-63639 -

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing th…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:55 p.m.

6.5

CVSS3.1

CVE-2025-63718 -

A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:38 p.m.

7.6

CVSS3.1

CVE-2025-63783 -

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user f…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 4:25 p.m.

6.1

CVSS3.1

CVE-2025-63638 -

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clic…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:46 p.m.

6.5

CVSS3.1

CVE-2025-63716 -

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:37 p.m.
Total resulsts: 349182
Page 3113 of 34,919
Β« previous page Β» next page
Filters