6.9

CVSS4.0

CVE-2025-9848 - ScriptAndTools Real Estate Management System userlist.php redirect

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publiโ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 6:12 p.m.

5.3

CVSS4.0

CVE-2025-9847 - ScriptAndTools Real Estate Management System register.php unrestricted upload

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to thโ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 6:14 p.m.

6.9

CVSS4.0

CVE-2025-57806 - Local Deep Research's API keys are stored in plain text

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. โ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, 12:47 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-9845 - code-projects Fruit Shop Management System products.php cross site scripting

A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such manipulation of the argument product_code/gen_name/product_name/supplier leads to cross site scripting. It is possible to launcโ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 1:57 p.m.

6.9

CVSS4.0

CVE-2025-9843 - Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ FindAll information disclosure

A flaw has been found in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information disclosure. It is possible to initiate the attack remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Sept. 3, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 7:46 p.m.

6.9

CVSS4.0

CVE-2025-9842 - Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ Search information disclosure

A vulnerability was detected in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used.

๐Ÿ“… Published: Sept. 3, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 7:48 p.m.

5.5

CVSS3.1

CVE-2025-38678 - netfilter: nf_tables: reject duplicate device on updates

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on updates A chain/flowtable update with duplicated devices in the same batch is possible. Unfortunately, netdev event path only removes the first device that is found, leaving unregiโ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

9.1

CVSS3.1

CVE-2025-57148 -

phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

๐Ÿ“… Published: Sept. 3, 2025, midnight ๐Ÿ”„ Last Modified: April 6, 2026, 3:17 p.m.

7.5

CVSS3.1

CVE-2025-55852 -

Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.

๐Ÿ“… Published: Sept. 3, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 8, 2025, 2:03 p.m.

8.4

CVSS3.1

CVE-2025-56803 -

Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted build field in the plugin's manifest.json. This field is passed to child_process.exec without validation, leading to poโ€ฆ

๐Ÿ“… Published: Sept. 3, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 26, 2025, 2:02 p.m.
Total resulsts: 349182
Page 4044 of 34,919
ยซ previous page ยป next page
Filters