5.3

CVSS4.0

CVE-2025-9651 - shafhasan chatbox chat.php sql injection

A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id results in sql injection. The attack may be performed from a remote location. The exploit has been made pub…

πŸ“… Published: Aug. 29, 2025, 2:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9650 - yeqifu carRental AppFileUtils.java removeFileByPath path traversal

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the function removeFileByPath of the file src/main/java/com/yeqifu/sys/utils/AppFileUtils.java. The manipulation of the argument carimg leads to path traversal. The attack is possible to …

πŸ“… Published: Aug. 29, 2025, 2:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-9649 - appneta tcpreplay send_packets.c calc_sleep_time divide by zero

A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to versio…

πŸ“… Published: Aug. 29, 2025, 1:32 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:19 p.m.

5.3

CVSS4.0

CVE-2025-9647 - mtons mblog list cross site scripting

A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could b…

πŸ“… Published: Aug. 29, 2025, 1:02 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 11:29 p.m.

5.1

CVSS4.0

CVE-2025-9646 - O2OA calendarConfig cross site scripting

A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organization_assemble_personal/jaxrs/definition/calendarConfig. The manipulation of the argument toMonthViewName results in cross site scripting. The attack can be launched remotely. T…

πŸ“… Published: Aug. 29, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 4:37 p.m.

6.9

CVSS4.0

CVE-2025-9645 - itsourcecode Apartment Management System r_all_info.php sql injection

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /t_dashboard/r_all_info.php. The manipulation of the argument mid leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be use…

πŸ“… Published: Aug. 29, 2025, 12:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:30 p.m.

6.9

CVSS4.0

CVE-2025-9644 - itsourcecode Apartment Management System bill_setup.php sql injection

A vulnerability was determined in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /setting/bill_setup.php. Executing manipulation of the argument txtBillType can lead to sql injection. It is possible to launch the attack remotely. The e…

πŸ“… Published: Aug. 29, 2025, 12:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:30 p.m.

6.9

CVSS4.0

CVE-2025-9643 - itsourcecode Apartment Management System utility_bill_setup.php sql injection

A vulnerability was found in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /setting/utility_bill_setup.php. Performing manipulation of the argument txtGasBill results in sql injection. It is possible to initiate the attack remot…

πŸ“… Published: Aug. 29, 2025, 12:02 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:31 p.m.

5.1

CVSS4.0

CVE-2025-40709 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:18 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:31 p.m.

5.1

CVSS4.0

CVE-2025-40708 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:18 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:32 p.m.
Total resulsts: 349182
Page 4088 of 34,919
Β« previous page Β» next page
Filters