8.9

CVSS4.0

CVE-2025-58453 - WeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'exibe_anexo.php' parameter 'id_anex…

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/exibe_anexo.php, in the id_anexo parameter. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, all…

📅 Published: Sept. 8, 2025, 10:28 p.m. 🔄 Last Modified: Sept. 17, 2025, 4:31 p.m.

2.1

CVSS4.0

CVE-2025-58452 - WeGIA vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint 'listar_despachos.php' paramet…

WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_despachos.php endpoint of the WeGIA application prior to version 3.4.11. This vulnerability allows attackers to inject malicious scripts in the id_memorando paramete…

📅 Published: Sept. 8, 2025, 10:26 p.m. 🔄 Last Modified: Sept. 17, 2025, 4:35 p.m.

5.9

CVSS3.1

CVE-2025-1761 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

📅 Published: Sept. 8, 2025, 10:13 p.m. 🔄 Last Modified: Sept. 17, 2025, 4:41 p.m.

8.7

CVSS4.0

CVE-2025-58451 - Cattown Vulnerable to Inefficient Regular Expression Complexity and Uncontrolled Resource Consumpti…

Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case complexity. This could cause excessive CPU usage due to excessive backtracking on crafted inputs. In turn, the excessive CPU usage could lead to resource ex…

📅 Published: Sept. 8, 2025, 10:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10108 - Campcodes Online Loan Management System ajax.php sql injection

A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and…

📅 Published: Sept. 8, 2025, 10:02 p.m. 🔄 Last Modified: Sept. 10, 2025, 6:02 p.m.

9.3

CVSS4.0

CVE-2025-58450 - pREST has Systemic SQL Injection Vulnerability

pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible in versions prior to 2.0.0-rc3. The validation present in versions prior to 2.0.0-rc3 does not provide adequate protection from injection attempts. Version 2.0.0-rc3 contains a p…

📅 Published: Sept. 8, 2025, 9:35 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10106 - yanyutao0402 ChanCMS search sql injection

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

📅 Published: Sept. 8, 2025, 9:32 p.m. 🔄 Last Modified: Sept. 10, 2025, 6:06 p.m.

8.7

CVSS4.0

CVE-2025-58449 - Maho Vulnerable to Authenticated Remote Code Execution via File Upload

Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the use…

📅 Published: Sept. 8, 2025, 9:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-58444 - MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted …

The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to in…

📅 Published: Sept. 8, 2025, 9:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-58365 - XWiki Blog Application: Privilege Escalation (PR) from account through blog content

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki allowed remote code execution for any user who has edit right on any page. Normally, these are all logged-in users as they can edit their own user prof…

📅 Published: Sept. 8, 2025, 9:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3960 of 34,919
« previous page » next page
Filters