6.5

CVSS3.1

CVE-2025-11683 - YAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Re…

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a has…

πŸ“… Published: Oct. 16, 2025, 12:14 a.m. πŸ”„ Last Modified: March 9, 2026, 3:05 p.m.

6.5

CVSS3.1

CVE-2025-61514 -

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-56699 -

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61330 -

A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/shadow configuration or even the absence of any password at …

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-60641 -

The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 and deserialized without validation or use of the allowed_classes option, allowing an att…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-60639 -

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-56700 -

Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-61543 -

A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing atta…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61540 -

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 10:18 a.m.

8.2

CVSS3.1

CVE-2025-22381 -

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3397 of 34,919
Β« previous page Β» next page
Filters