4.5

CVSS3.1

CVE-2025-9913 - Cross Site Scripting: Session Hijacking

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

๐Ÿ“… Published: Oct. 6, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 1:55 a.m.

8.7

CVSS4.0

CVE-2025-11324 - Tenda AC18 setNotUpgrade stack-based overflow

A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 6:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:44 a.m.

8.7

CVSS4.0

CVE-2025-11323 - UTT 1250GW formUserStatusRemark strcpy buffer overflow

A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed andโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 6:02 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 4:03 p.m.

6.3

CVSS3.1

CVE-2025-9710 - Responsive Lightbox & Gallery < 2.5.3 - Unauthenticated Stored-XSS via Comments

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.

๐Ÿ“… Published: Oct. 6, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-9703 - Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

๐Ÿ“… Published: Oct. 6, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-11322 - Mangati NovoSGA User Creation new weak password

A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmaรงรฃo da senha can lead to weak password requirements. The attack can be launchedโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-57781 -

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

๐Ÿ“… Published: Oct. 6, 2025, 5:16 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11321 - zhuimengshaonian wisdom-education WrongBookController.java authorization

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the argument subjectId results in authorization bypass. The โ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11320 - zhuimengshaonian wisdom-education UploadController.java uploadFile unrestricted upload

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argument File leads to unrestricted upload. It is possible to launโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11319 - nahiduddinahammed Hospital-Management-System-Website delete.php sql injection

A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the argument ai causes sql injection. It is possible to initiate the attackโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3547 of 34,919
ยซ previous page ยป next page
Filters