6.5

CVSS3.1

CVE-2025-60427 -

LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the Web UI and direct API calls. The backend does not verify role-based permissions for analytics endpoints, allowing unauthorized retrieval of station-w…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-56450 -

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this by sending a specially crafted POST request, resulting in the execution of arbitrary SQL queries…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-60280 -

Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly i…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 2:48 p.m.

5

CVSS3.1

CVE-2025-62763 -

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-61220 -

The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauthorized access to their personal information.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS3.1

CVE-2025-60507 -

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Admin…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-60751 -

GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2025-56801 -

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that mat…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:46 p.m.

5.1

CVSS3.1

CVE-2025-56800 -

Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaS…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:46 p.m.

6.1

CVSS3.1

CVE-2025-61457 -

code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3360 of 34,919
Β« previous page Β» next page
Filters