5.1

CVSS4.0

CVE-2025-10993 - MuYuCMS Template Management admin.php code injection

A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the component Template Management. The manipulation results in code injection. It is possible to launch the attack remotely.

πŸ“… Published: Sept. 26, 2025, 1:32 a.m. πŸ”„ Last Modified: Oct. 3, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-10992 - roncoo roncoo-pay lookupList improper authorization

A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unknown function of the file /user/info/lookupList. Executing manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly di…

πŸ“… Published: Sept. 26, 2025, 1:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10989 - yangzongzhuan RuoYi selectAll improper authorization

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can be initiated remotely. The exploit has been …

πŸ“… Published: Sept. 26, 2025, 12:32 a.m. πŸ”„ Last Modified: Oct. 3, 2025, 8:23 p.m.

5.3

CVSS4.0

CVE-2025-10988 - YunaiV ruoyi-vue-pro transfer improper authorization

A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was…

πŸ“… Published: Sept. 26, 2025, 12:32 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 11:43 p.m.

5.3

CVSS4.0

CVE-2025-10987 - YunaiV yudao-cloud HTTP Request transfer improper authorization

A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component HTTP Request Handler. This manipulation of the argument contactId causes improper authorization. It is possible to initiate the…

πŸ“… Published: Sept. 26, 2025, 12:02 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 11:42 p.m.

5.3

CVSS4.0

CVE-2025-10981 - JeecgBoot exportXls improper authorization

A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about…

πŸ“… Published: Sept. 26, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 12:59 a.m.

8.4

CVSS3.1

CVE-2025-56383 -

Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivilege…

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-45994 -

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 7:28 p.m.

5

CVSS3.1

CVE-2025-60251 -

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-57292 -

Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 7:05 p.m.
Total resulsts: 349182
Page 3677 of 34,919
Β« previous page Β» next page
Filters