6.5

CVSS3.1

CVE-2025-56162 -

YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin pas…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 6:33 p.m.

6.1

CVSS3.1

CVE-2025-61087 -

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2025-56154 -

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 6:16 p.m.

5.3

CVSS3.1

CVE-2025-60661 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 5:30 p.m.

6.5

CVSS3.1

CVE-2025-56380 -

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 4:18 p.m.

9.3

CVSS4.0

CVE-2025-61588 - risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the…

πŸ“… Published: Oct. 1, 2025, 11:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-61583 - TS3 Manager is vulnerable to unauthenticated reflected XSS attack due to insecure error handling

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames …

πŸ“… Published: Oct. 1, 2025, 10:27 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 6:07 p.m.

7.5

CVSS3.1

CVE-2025-61582 - Ts3 Manager: Unauthenticated Denial of Service possible through specially crafted Unicode input

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability permits an unauthenticated actor to crash the application through the submission of specially crafted Unicode input, requiri…

πŸ“… Published: Oct. 1, 2025, 10:20 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 6:07 p.m.

2.1

CVSS4.0

CVE-2025-61587 - Weblate integration with Anubis can lead to Open Redirect via redir parameter

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attack…

πŸ“… Published: Oct. 1, 2025, 10:01 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 2:26 p.m.

9.2

CVSS4.0

CVE-2025-59951 - Termix' official Docker image contains an authentication bypass vulnerability

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the backend to retrieve the proxy's IP instead of the client's IP…

πŸ“… Published: Oct. 1, 2025, 9:52 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 6:37 p.m.
Total resulsts: 349182
Page 3600 of 34,919
Β« previous page Β» next page
Filters