2.3

CVSS4.0

CVE-2025-10080 - running-elephant Datart API AESUtil.java getTokensecret hard-coded key

A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipulation leads to use of hard-coded cryptographic key . The attโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10079 - PHPGurukul Small CRM get-quote.php sql injection

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Sept. 8, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 3:54 p.m.

6.9

CVSS4.0

CVE-2025-10078 - SourceCodester Online Polling System candidates.php sql injection

A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

๐Ÿ“… Published: Sept. 8, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 4:51 p.m.

6.9

CVSS4.0

CVE-2025-10077 - SourceCodester Online Polling System registeracc.php sql injection

A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and mayโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:52 p.m.

6.9

CVSS4.0

CVE-2025-10076 - SourceCodester Online Polling System manage-profile.php sql injection

A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and couโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:52 p.m.

5.1

CVSS4.0

CVE-2025-10075 - SourceCodester Online Polling System manage-profile.php cross site scripting

A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been releaseโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:52 p.m.

5.1

CVSS4.0

CVE-2025-10074 - Portabilis i-Educar tipos cross site scripting

A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument Tipos de Usuรกrio/Descriรงรฃo leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly availaโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:52 p.m.

9.8

CVSS3.1

CVE-2025-57285 -

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 12, 2025, 8:37 p.m.

9.8

CVSS3.1

CVE-2025-56266 -

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 12, 2025, 8:44 p.m.

7.5

CVSS3.1

CVE-2025-52288 -

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a denial of service or other unspecified impacts via repeated UE connect and disconnect messagโ€ฆ

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 6:19 p.m.
Total resulsts: 349182
Page 3966 of 34,919
ยซ previous page ยป next page
Filters