9.4

CVSS4.0

CVE-2025-34292 - BeWelcome/Rox PHP Object Injection RCE

Rox, the software running BeWelcome,ย contains a PHP object injection vulnerabilityย resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in \\RoxPostHandler::getCallbackAction and the 'memory cookie' reโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 2:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-12288 - Bdtask Pharmacy Management System User Profile edit_user authorization

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is nowโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 2:32 p.m. ๐Ÿ”„ Last Modified: Nov. 24, 2025, 12:16 p.m.

5.1

CVSS4.0

CVE-2025-12287 - Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may โ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 2:32 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 5:06 p.m.

7.3

CVSS4.0

CVE-2025-12286 - VeePN AVService avservice.exe unquoted search path

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of complexity is needed fโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-12283 - code-projects Client Details System authorization

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

๐Ÿ“… Published: Oct. 27, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 4:50 p.m.

8.8

CVSS4.0

CVE-2025-9164 - Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 1:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-50055 -

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter

๐Ÿ“… Published: Oct. 27, 2025, 1:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-12282 - code-projects Client Details System manage-users.php cross site scripting

A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.

๐Ÿ“… Published: Oct. 27, 2025, 1:32 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 4:43 p.m.

4.8

CVSS4.0

CVE-2025-12281 - code-projects Client Details System clientview.php cross site scripting

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utiโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 1:32 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 5:41 p.m.

4.8

CVSS4.0

CVE-2025-12280 - code-projects Client Details System update-clients.php cross site scripting

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be usโ€ฆ

๐Ÿ“… Published: Oct. 27, 2025, 1:32 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 5:42 p.m.
Total resulsts: 349182
Page 3258 of 34,919
ยซ previous page ยป next page
Filters