6.1

CVSS3.1

CVE-2025-51967 -

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's …

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:43 p.m.

9.8

CVSS3.1

CVE-2025-55583 -

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitizat…

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:41 p.m.

5.3

CVSS3.1

CVE-2025-57218 -

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 3, 2025, 4:11 p.m.

2.4

CVSS3.1

CVE-2025-51643 -

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of se…

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:51 p.m.

6.5

CVSS3.1

CVE-2025-51968 -

A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:43 p.m.

5.4

CVSS3.1

CVE-2025-51971 -

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inje…

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:42 p.m.

6.1

CVSS3.1

CVE-2025-56236 -

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser c…

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:41 p.m.

9.3

CVSS4.0

CVE-2024-13979 - St. Joe ERP System SingleRowQueryConverter SQL Injection

A SQL injection vulnerability exists in the St. Joe ERP system ("εœ£δΉ”ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into…

πŸ“… Published: Aug. 27, 2025, 9:27 p.m. πŸ”„ Last Modified: Nov. 28, 2025, 10:22 p.m.

8.7

CVSS4.0

CVE-2024-13982 - SPON IP Network Intercom System rj_get_token.php Arbitrary File Read

SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perf…

πŸ“… Published: Aug. 27, 2025, 9:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2023-7308 - SecGate3600 Firewall Information Disclosure via authManageSet.cgi

SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An unauthenticated remot…

πŸ“… Published: Aug. 27, 2025, 9:26 p.m. πŸ”„ Last Modified: Nov. 28, 2025, 9:41 p.m.
Total resulsts: 349182
Page 4115 of 34,919
Β« previous page Β» next page
Filters