6.9

CVSS4.0

CVE-2025-9669 - Jinher OA GetTreeDate.aspx sql injection

A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Aug. 29, 2025, 7:02 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 8:42 p.m.

4.6

CVSS4.0

CVE-2025-43773 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for imprope…

πŸ“… Published: Aug. 29, 2025, 6:59 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:56 p.m.

5.3

CVSS4.0

CVE-2025-9667 - code-projects Simple Grading System Admin Panel delete_account.php sql injection

A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delete_account.php of the component Admin Panel. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public an…

πŸ“… Published: Aug. 29, 2025, 6:32 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2025-9666 - code-projects Simple Grading System Admin Panel delete_student.php sql injection

A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some unknown functionality of the file /delete_student.php of the component Admin Panel. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely.…

πŸ“… Published: Aug. 29, 2025, 6:02 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-58158 - Harness Affected by Arbitrary File Write in Gitness LFS server

Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open Source Harness git LFS server (Gitness) exposes api to retrieve and upload files via git LFS. Implementation …

πŸ“… Published: Aug. 29, 2025, 5:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9665 - code-projects Simple Grading System Admin Panel edit_student.php sql injection

A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_student.php of the component Admin Panel. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The expl…

πŸ“… Published: Aug. 29, 2025, 5:32 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

8.6

CVSS4.0

CVE-2025-9377 - Authenticated RCE via Parental Control command injection

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control pageΒ onΒ TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 andΒ TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-…

πŸ“… Published: Aug. 29, 2025, 5:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7

CVSS4.0

CVE-2025-52861 - VioStor

A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: VioStor 5.1.6 …

πŸ“… Published: Aug. 29, 2025, 5:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-52856 - VioStor

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

πŸ“… Published: Aug. 29, 2025, 5:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

2.3

CVSS4.0

CVE-2025-44015 - HybridDesk Station

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk Station 4.2.18 and later

πŸ“… Published: Aug. 29, 2025, 5:17 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 3:32 p.m.
Total resulsts: 349182
Page 4081 of 34,919
Β« previous page Β» next page
Filters