5.4

CVSS3.1

CVE-2025-59412 - CubeCart Vulnerable to HTML Injection in Product Reviews Allows Malicious Links and Defacement

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approve…

πŸ“… Published: Sept. 22, 2025, 4:14 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:50 p.m.

5.4

CVSS3.1

CVE-2025-59411 - CubeCart Stored/Reflected HTML Injection Vulnerability in Contact Enquiry

CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verbatim in the email sent to the store admin. By submitting HTML in the Enquiry, the admin receives an email containing that HTML. This indicates user in…

πŸ“… Published: Sept. 22, 2025, 4:14 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:51 p.m.

7.1

CVSS3.1

CVE-2025-59335 - CubeCart Session Not Invalidated After Password Change

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user …

πŸ“… Published: Sept. 22, 2025, 4:13 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:51 p.m.

5.3

CVSS4.0

CVE-2025-10805 - Campcodes Online Beauty Parlor Management System add-services.php sql injection

A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of the file /admin/add-services.php. Executing manipulation of the argument sername can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disc…

πŸ“… Published: Sept. 22, 2025, 4:02 p.m. πŸ”„ Last Modified: Sept. 24, 2025, 8:26 p.m.

9.3

CVSS4.0

CVE-2025-35042 - Airship AI Acropolis default credentials

Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed in 10.2.35, 11.0.21,…

πŸ“… Published: Sept. 22, 2025, 3:57 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 12:28 p.m.

7.7

CVSS4.0

CVE-2025-35041 - Airship AI Acropolis MFA insufficient rate limiting

Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.

πŸ“… Published: Sept. 22, 2025, 3:56 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 12:30 p.m.

5.3

CVSS4.0

CVE-2025-10804 - Campcodes Online Beauty Parlor Management System add-customer.php sql injection

A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add-customer.php. Performing manipulation of the argument mobilenum results in sql injection. The attack can be initiated remotely. The exploit …

πŸ“… Published: Sept. 22, 2025, 3:32 p.m. πŸ”„ Last Modified: Sept. 24, 2025, 8:25 p.m.

5.4

CVSS3.1

CVE-2025-36037 - IBM webMethods Integration server-side request forgery

IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: Sept. 22, 2025, 3:17 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 7:12 p.m.

7.5

CVSS3.1

CVE-2025-36202 - IBM webMethods Integration code execution

IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.

πŸ“… Published: Sept. 22, 2025, 3:14 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 7:13 p.m.

8.7

CVSS4.0

CVE-2025-10803 - Tenda AC23 HTTP POST Request SetPptpServerCfg sscanf buffer overflow

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the att…

πŸ“… Published: Sept. 22, 2025, 3:02 p.m. πŸ”„ Last Modified: Sept. 24, 2025, 8:25 p.m.
Total resulsts: 349182
Page 3751 of 34,919
Β« previous page Β» next page
Filters