6.9

CVSS4.0

CVE-2025-11343 - code-projects Student Crud Operation delete.php sql injection

A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function of the file delete.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and …

πŸ“… Published: Oct. 6, 2025, 6:02 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 3:38 p.m.

7.5

CVSS3.1

CVE-2025-6985 - XXE Vulnerability in langchain-ai/langchain

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.X…

πŸ“… Published: Oct. 6, 2025, 5:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-11342 - code-projects Online Course Registration edit-course.php sql injection

A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode can lead to sql injection. The attack can be executed remotely. The exploit has been made available …

πŸ“… Published: Oct. 6, 2025, 5:32 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-11341 - Jinher OA type xml external entity reference

A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The …

πŸ“… Published: Oct. 6, 2025, 5:02 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:55 p.m.

7.3

CVSS3.1

CVE-2025-36354 - IBM Security Verify Access command execution

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.

πŸ“… Published: Oct. 6, 2025, 4:53 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 7:23 p.m.

9.3

CVSS4.0

CVE-2025-61778 - Akka.Remote TLS did not properly implement certificate-based authentication

Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of inbound connections. A…

πŸ“… Published: Oct. 6, 2025, 4:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-36355 - IBM Security Verify Access code execution

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

πŸ“… Published: Oct. 6, 2025, 4:52 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 7:23 p.m.

9.3

CVSS3.1

CVE-2025-36356 - IBM Security Verify Access privilege escalation

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.

πŸ“… Published: Oct. 6, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 7:20 p.m.

9.4

CVSS3.1

CVE-2025-61777 - FlagForge Allows Unauthenticated Badge Template API Access

Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints previously allowed access without authentication or authorization. This could have enabled unauthori…

πŸ“… Published: Oct. 6, 2025, 4:44 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 11:09 p.m.

10

CVSS4.0

CVE-2025-10363 - Unauthenticated RCE via .NET Deserialization in Topal Finance Software

Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00

πŸ“… Published: Oct. 6, 2025, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3541 of 34,919
Β« previous page Β» next page
Filters