6.9

CVSS4.0

CVE-2025-10479 - SourceCodester Online Student File Management System index.php sql injection

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been rโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: Sept. 17, 2025, 4:48 p.m.

6.3

CVSS4.0

CVE-2025-55211 - FreePBX Post-Authenticated Command Injection

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.

๐Ÿ“… Published: Sept. 15, 2025, 9 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 9:57 p.m.

2.1

CVSS4.0

CVE-2025-43798 -

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a userโ€™s TOTP to authenticate as the user.

๐Ÿ“… Published: Sept. 15, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:36 p.m.

8.8

CVSS4.0

CVE-2025-59145 - [email protected] contains malware after npm account takeover

color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency โ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10477 - kidaze CourseSelectionSystem eligibility.php sql injection

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/PriProfile/eligibility.php. Such manipulation of the argument Branch leads to sql injection. The attack can be launched rโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2025, 2:49 p.m.

6.9

CVSS4.0

CVE-2025-43799 -

Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, whichโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:19 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:37 p.m.

8.6

CVSS3.1

CVE-2025-59332 - 3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which meansโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-59154 - Openfire allows potential identity spoofing via unsafe CN parsing

Openfire is an XMPP server licensed under the Open Source Apache License. Openfireโ€™s SASL EXTERNAL mechanism for client TLS authentication contains a vulnerability in how it extracts user identities from X.509 certificates. Instead of parsing the structured ASN.1 data, the code calls X509Certificatโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-10475 - SpyShelter IOCTL SpyShelter.sys denial of service

A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelter.sys of the component IOCTL Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been made available to the public and coโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59331 - [email protected] contains malware after npm account takeover

is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirecโ€ฆ

๐Ÿ“… Published: Sept. 15, 2025, 7:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3852 of 34,919
ยซ previous page ยป next page
Filters