9.8

CVSS3.1

CVE-2025-63685 -

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's s…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

4.3

CVSS3.1

CVE-2025-65223 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:25 p.m.

7.5

CVSS3.1

CVE-2025-63889 -

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

9.8

CVSS3.1

CVE-2025-63807 -

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authen…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

6.5

CVSS3.1

CVE-2025-60794 -

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

9.8

CVSS3.1

CVE-2025-52410 -

Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

7.5

CVSS3.1

CVE-2025-63700 -

An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

6.1

CVSS3.1

CVE-2025-64027 -

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify th…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

7.5

CVSS3.1

CVE-2025-25613 -

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were transmitted in cleartext using…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:11 a.m.

7.5

CVSS3.1

CVE-2025-61138 -

Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.
Total resulsts: 319219
Page 35 of 31,922
Β« previous page Β» next page
Filters