8.8

CVSS3.1

CVE-2025-52389 -

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request.

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-55998 -

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 29, 2025, 6:15 p.m.

3.7

CVSS3.1

CVE-2025-51586 -

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

๐Ÿ“… Published: Sept. 8, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 12, 2025, 8:49 p.m.

5.3

CVSS4.0

CVE-2025-10073 - Portabilis i-Educar turma improper authorization

A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

๐Ÿ“… Published: Sept. 7, 2025, 11:32 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:52 p.m.

5.3

CVSS4.0

CVE-2025-10072 - Portabilis i-Educar enturmar access control

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and coโ€ฆ

๐Ÿ“… Published: Sept. 7, 2025, 11:02 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:51 p.m.

5.3

CVSS4.0

CVE-2025-10071 - Portabilis i-Educar cancelar-enturmacao-em-lote access control

A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed to the public and may be โ€ฆ

๐Ÿ“… Published: Sept. 7, 2025, 10:32 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:45 p.m.

5.3

CVSS4.0

CVE-2025-10070 - Portabilis i-Educar enturmacao-em-lote access control

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes improper access controls. The attack is possible to be carried out remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Sept. 7, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:44 p.m.

7.1

CVSS4.0

CVE-2025-48042 - Before action hooks may execute in certain scenarios despite a request being forbidden

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines โ€ฆ

๐Ÿ“… Published: Sept. 7, 2025, 4:01 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10068 - itsourcecode Online Discussion Forum add_views.php sql injection

A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/admin_forum/add_views.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and mayโ€ฆ

๐Ÿ“… Published: Sept. 7, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 4:54 p.m.

5.3

CVSS4.0

CVE-2025-10067 - itsourcecode POS Point of Sale System empty_table.php cross site scripting

A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Performing manipulation of the argument scripts results in cross site scripting. It is possibโ€ฆ

๐Ÿ“… Published: Sept. 7, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 5 p.m.
Total resulsts: 349182
Page 3968 of 34,919
ยซ previous page ยป next page
Filters