5.3

CVSS4.0

CVE-2025-10485 - pojoin h3blog HTTP Header login ppt_log cross site scripting

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be …

πŸ“… Published: Sept. 15, 2025, 10:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10483 - SourceCodester Online Student File Management System save_user.php sql injection

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The ex…

πŸ“… Published: Sept. 15, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 5:07 p.m.

6.9

CVSS4.0

CVE-2025-10482 - SourceCodester Online Student File Management System index.php sql injection

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

πŸ“… Published: Sept. 15, 2025, 10:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 5:05 p.m.

5.3

CVSS4.0

CVE-2025-10481 - SourceCodester Online Student File Management System remove_file.php sql injection

A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disc…

πŸ“… Published: Sept. 15, 2025, 10:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 5 p.m.

4.8

CVSS4.0

CVE-2025-43802 -

Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arb…

πŸ“… Published: Sept. 15, 2025, 9:58 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-10480 - SourceCodester Online Student File Management System save_file.php unrestricted upload

A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and…

πŸ“… Published: Sept. 15, 2025, 9:32 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:59 p.m.

5.3

CVSS4.0

CVE-2025-43797 -

In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is β€œOpen” which allows any registered users to become a member o…

πŸ“… Published: Sept. 15, 2025, 9:28 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:22 p.m.

4.8

CVSS4.0

CVE-2025-6947 - WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the SIP Proxy module. This vulnerability requires an authenticated administrator session to a locally managed Firebox. This issue affects Firebo…

πŸ“… Published: Sept. 15, 2025, 9:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-6999 - WatchGuard Firebox Authentication Portal Request Smuggling Vulnerability

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.This issue affects Fireware OS: from 12.0 through 12.11.2.

πŸ“… Published: Sept. 15, 2025, 9:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-59056 - FreePBX vulnerable to unauthenticated Denial of Service

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most…

πŸ“… Published: Sept. 15, 2025, 9:04 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 10 p.m.
Total resulsts: 349182
Page 3851 of 34,919
Β« previous page Β» next page
Filters