5.3

CVSS4.0

CVE-2025-9687 - Portabilis i-Educar processamentoApi improper authorization

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Executing manipulation can lead to improper authorization. The attack may be performed from a remote location. The exploit has been made available…

📅 Published: Aug. 30, 2025, 12:02 p.m. 🔄 Last Modified: Sept. 4, 2025, 4:50 p.m.

5.3

CVSS4.0

CVE-2025-9686 - Portabilis i-Educar Listagem de áreas de conhecimento edit sql injection

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component Listagem de áreas de conhecimento Page. Performing manipulation of the argument ID results in sql injection. The attack is pos…

📅 Published: Aug. 30, 2025, 11:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 4:50 p.m.

5.3

CVSS4.0

CVE-2025-9685 - Portabilis i-Educar Listagem de áreas de conhecimento view sql injection

A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remote…

📅 Published: Aug. 30, 2025, 11:02 a.m. 🔄 Last Modified: Sept. 4, 2025, 4:50 p.m.

5.3

CVSS4.0

CVE-2025-9684 - Portabilis i-Educar Formula de Cálculo de Média edit sql injection

A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/edit of the component Formula de Cálculo de Média Page. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The explo…

📅 Published: Aug. 30, 2025, 10:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 4:50 p.m.

5.1

CVSS4.0

CVE-2025-9683 - O2OA Personal Profile form cross site scripting

A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit has been m…

📅 Published: Aug. 30, 2025, 10:02 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:09 p.m.

5.1

CVSS4.0

CVE-2025-9682 - O2OA Personal Profile appdict cross site scripting

A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. Th…

📅 Published: Aug. 30, 2025, 9:32 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:38 p.m.

5.1

CVSS4.0

CVE-2025-9681 - O2OA Personal Profile agent cross site scripting

A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be use…

📅 Published: Aug. 30, 2025, 8:32 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:46 p.m.

5.1

CVSS4.0

CVE-2025-9680 - O2OA Personal Profile page cross site scripting

A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting. The attack can be initiated remotely. The exploit is now public a…

📅 Published: Aug. 30, 2025, 7:02 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:49 p.m.

6.9

CVSS4.0

CVE-2025-9679 - itsourcecode Student Information System course_edit1.php sql injection

A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed public…

📅 Published: Aug. 30, 2025, 4:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 4:51 p.m.

6.4

CVSS3.1

CVE-2025-9500 - TablePress <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Pa…

The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces…

📅 Published: Aug. 30, 2025, 4:25 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.
Total resulsts: 349182
Page 4077 of 34,919
« previous page » next page
Filters