6.5

CVSS3.1

CVE-2025-60797 -

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authent…

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 21, 2025, 4:16 p.m.

4.3

CVSS3.1

CVE-2025-65220 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

📅 Published: Nov. 20, 2025, midnight 🔄 Last Modified: Nov. 21, 2025, 5:26 p.m.

5.1

CVSS4.0

CVE-2025-13423 - Campcodes Retro Basketball Shoes Online Store admin_product.php unrestricted upload

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has be…

📅 Published: Nov. 19, 2025, 11:32 p.m. 🔄 Last Modified: Nov. 21, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-13422 - freeprojectscodes Sports Club Management System change_s_pwd.php sql injection

A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation of the argument login_id results in sql injection. The attack may be initiated remotely. The exploi…

📅 Published: Nov. 19, 2025, 11:32 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-13421 - itsourcecode Human Resource Management System NoticeStore.php sql injection

A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argument noticeDesc leads to sql injection. The attack can be launched remotely. The exploit has been dis…

📅 Published: Nov. 19, 2025, 11:02 p.m. 🔄 Last Modified: Nov. 21, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-13420 - itsourcecode Human Resource Management System EventStore.php sql injection

A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument eventSubject causes sql injection. The attack can be initiated remotely. The exploit has been made…

📅 Published: Nov. 19, 2025, 10:32 p.m. 🔄 Last Modified: Nov. 24, 2025, 9:11 a.m.

5.1

CVSS4.0

CVE-2025-13415 - icret EasyImages SVG Image upload.php cross site scripting

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely.

📅 Published: Nov. 19, 2025, 10:02 p.m. 🔄 Last Modified: Nov. 24, 2025, 9:10 a.m.

7

CVSS3.0

CVE-2025-11001 - 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on t…

📅 Published: Nov. 19, 2025, 9:16 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

2.3

CVSS4.0

CVE-2025-11884 - Cross-site Scripting vulnerability discovered in OpenText™ Universal Discovery and CMDB

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker has high level access to UCMDB to create or update data with malicious scripts This issue affects uCMDB: 24.4.

📅 Published: Nov. 19, 2025, 9:13 p.m. 🔄 Last Modified: Nov. 24, 2025, 9:10 a.m.

4.8

CVSS4.0

CVE-2025-13412 - Campcodes Retro Basketball Shoes Online Store admin_running.php cross site scripting

A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remo…

📅 Published: Nov. 19, 2025, 9:02 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319197
Page 34 of 31,920
« previous page » next page
Filters