6.9

CVSS4.0

CVE-2025-9662 - code-projects Simple Grading System Admin Panel login.php sql injection

A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file /login.php of the component Admin Panel. Executing manipulation can lead to sql injection. The attack may be performed from a remote location. The exploit has been publicly discloโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:50 p.m.

6.9

CVSS4.0

CVE-2025-9660 - SourceCodester Bakeshop Online Ordering System passwordrecover.php sql injection

A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploitโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:48 p.m.

0.0

CVE-2025-58375 -

This CVE is a duplicate of another CVE.

๐Ÿ“… Published: Aug. 29, 2025, 4:19 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 11:47 p.m.

5.1

CVSS4.0

CVE-2025-9659 - O2OA Personal Profile widget cross site scripting

A vulnerability has been found in O2OA up to 10.0-410. The affected element is an unknown function of the file /x_portal_assemble_designer/jaxrs/widget of the component Personal Profile Page. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:19 p.m.

5.1

CVSS4.0

CVE-2025-9658 - O2OA Personal Profile dict cross site scripting

A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/jaxrs/dict/ of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting. Remote exploitation of the attack is possibโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:27 p.m.

7.3

CVSS3.1

CVE-2025-47909 - Improper validation of TrustedOrigins allows CSRF attacks in github.com/gorilla/csrf

Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks. After the CVE-2025-24358 fix, a network attacker that places a form at http://example.com can't get it to submit to https://example.com because the Origin heโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-55750 - Gitpod Classic Affected by Bitbucket OAuth Token Exposure via Redirect Fragment

Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket in certain conditions allowed a crafted link to expose a valid Bitbucket access token via the URL fragment wheโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 3:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-55177 -

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a targetโ€™s device. We aโ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 3:50 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.3

CVSS4.0

CVE-2025-5808 - Authentication Bypass vulnerability discovered in the OpenTextโ„ข Self-Service Password Reset

Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3.

๐Ÿ“… Published: Aug. 29, 2025, 3:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-55202 - Opencast has a partial path traversal vulnerability in UI config

Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partially allowing for attacks in very specific cases. โ€ฆ

๐Ÿ“… Published: Aug. 29, 2025, 3:35 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:09 p.m.
Total resulsts: 349182
Page 4086 of 34,919
ยซ previous page ยป next page
Filters