5.3

CVSS3.1

CVE-2025-56498 -

An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sanitized. An authenticated attacker can exploit th…

πŸ“… Published: Sept. 3, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 3:58 p.m.

7.5

CVSS3.1

CVE-2025-54588 - Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a use-after-free (UAF) vulnerability in the DNS cache, causing abnormal process termination. The vulnerability is in Envoy's Dynamic For…

πŸ“… Published: Sept. 2, 2025, 11:39 p.m. πŸ”„ Last Modified: Sept. 8, 2025, 3:19 p.m.

5.3

CVSS4.0

CVE-2025-9841 - code-projects Mobile Shop Management System AddNewProduct.php unrestricted upload

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit h…

πŸ“… Published: Sept. 2, 2025, 11:32 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.5

CVSS3.1

CVE-2025-9260 - Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated atta…

πŸ“… Published: Sept. 2, 2025, 11:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9840 - itsourcecode Sports Management System gametype.php sql injection

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available t…

πŸ“… Published: Sept. 2, 2025, 11:02 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 5:35 p.m.

6.9

CVSS4.0

CVE-2025-9839 - itsourcecode Student Information Management System index.php sql injection

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible.…

πŸ“… Published: Sept. 2, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 5:37 p.m.

6.9

CVSS4.0

CVE-2025-9838 - itsourcecode Student Information Management System index.php sql injection

A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available…

πŸ“… Published: Sept. 2, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 5:38 p.m.

9.8

CVSS3.1

CVE-2025-26416 -

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Sept. 2, 2025, 10:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

7

CVSS3.1

CVE-2025-22442 -

In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not …

πŸ“… Published: Sept. 2, 2025, 10:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

7.3

CVSS3.1

CVE-2025-22439 -

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

πŸ“… Published: Sept. 2, 2025, 10:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.
Total resulsts: 349182
Page 4047 of 34,919
Β« previous page Β» next page
Filters