5.3

CVSS4.0

CVE-2025-11288 - CRMEB GET Parameter product sql injection

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injection. Remote exploitation of the attack is possible.…

πŸ“… Published: Oct. 5, 2025, 7:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

6.9

CVSS4.0

CVE-2025-11287 - samanhappy MCPHub sseService.ts handleSseConnectionfunction improper authentication

A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available an…

πŸ“… Published: Oct. 5, 2025, 7:02 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 5:18 p.m.

5.1

CVSS4.0

CVE-2025-11286 - samanhappy MCPHub MCPRouter Service serverController.ts server-side request forgery

A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controllers/serverController.ts of the component MCPRouter Service. This manipulation of the argument baseUrl causes server-side request forgery. The attack may be initiated remotely. The …

πŸ“… Published: Oct. 5, 2025, 6:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 5:18 p.m.

5.3

CVSS4.0

CVE-2025-11285 - samanhappy MCPHub serverController.ts os command injection

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of the argument command/args results in os command injection. The attack can be launched remotely. The exploit has been…

πŸ“… Published: Oct. 5, 2025, 6:02 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 5:16 p.m.

6.9

CVSS4.0

CVE-2025-11284 - Zytec Dalian Zhuoyun Technology Central Authentication Service HTTP Header git hard-coded password

A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of har…

πŸ“… Published: Oct. 5, 2025, 5:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-11283 - Frappe LMS Course cross site scripting

A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilize…

πŸ“… Published: Oct. 5, 2025, 5:02 a.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:37 p.m.

4.8

CVSS4.0

CVE-2025-11282 - Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting

A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be …

πŸ“… Published: Oct. 5, 2025, 4:32 a.m. πŸ”„ Last Modified: March 25, 2026, 1:16 p.m.

2.3

CVSS4.0

CVE-2025-11281 - Frappe LMS Unpublished Course courses access control

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is characterized by high complexi…

πŸ“… Published: Oct. 5, 2025, 4:02 a.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:35 p.m.

6.3

CVSS4.0

CVE-2025-11280 - Frappe LMS Assignment Picture files direct request

A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered diff…

πŸ“… Published: Oct. 5, 2025, 3:32 a.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:35 p.m.

9.8

CVSS3.1

CVE-2025-61882 -

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Co…

πŸ“… Published: Oct. 5, 2025, 3:17 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 3554 of 34,919
Β« previous page Β» next page
Filters