5.4

CVSS3.1

CVE-2025-45585 -

Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the wifi_sta_ssid or wifi_ap_ssid parameters.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:37 p.m.

6.1

CVSS3.1

CVE-2025-52074 -

PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-45584 -

Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:37 p.m.

9.8

CVSS3.1

CVE-2024-45434 -

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this t…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 8 p.m.

9.8

CVSS3.1

CVE-2025-55835 -

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:47 p.m.

5.1

CVSS4.0

CVE-2025-10273 - erjinzhi 10OA file.aspx path traversal

A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such manipulation of the argument File leads to path traversal. The exploit is publicly available and might be used. The vendor was contacted early about this…

πŸ“… Published: Sept. 11, 2025, 11:32 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:25 p.m.

5.3

CVSS4.0

CVE-2025-10272 - erjinzhi 10OA catalogue cross site scripting

A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor wa…

πŸ“… Published: Sept. 11, 2025, 11:02 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:26 p.m.

5.7

CVSS3.1

CVE-2025-11060 - Surrealdb: surrealdb is vulnerable to unauthorized data exposure via live query subscriptions

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.

πŸ“… Published: Sept. 11, 2025, 9:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10271 - erjinzhi 10OA finder cross site scripting

A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The manipulation of the argument Name results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was con…

πŸ“… Published: Sept. 11, 2025, 9:32 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:27 p.m.

8.7

CVSS3.1

CVE-2025-36222 - IBM Fusion insecure default configuration

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.

πŸ“… Published: Sept. 11, 2025, 8:44 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 3898 of 34,919
Β« previous page Β» next page
Filters