6.9

CVSS4.0

CVE-2025-8967 - itsourcecode Online Tour and Travel Management System packages.php sql injection

A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 3:33 p.m.

5.3

CVSS3.1

CVE-2025-33142 - IBM WebSphere Application Server information disclosure

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

๐Ÿ“… Published: Aug. 14, 2025, 3:41 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 6:05 p.m.

5.3

CVSS3.1

CVE-2025-36047 - IBM WebSphere Application Server Liberty denial of service

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

๐Ÿ“… Published: Aug. 14, 2025, 3:38 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

6.9

CVSS4.0

CVE-2025-8966 - itsourcecode Online Tour and Travel Management System tax.php sql injection

A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argument tname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 3:33 p.m.

5.3

CVSS4.0

CVE-2025-8965 - linlinjava litemall Endpoint AdminStorageController.java create unrestricted upload

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unreโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 3:12 p.m.

5.3

CVSS4.0

CVE-2025-53631 - flaskBlog XSS Vulnerability in postContent

flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the uโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 3:26 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 9:29 p.m.

8.7

CVSS3.1

CVE-2025-40758 -

A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All versions < V4.1.2), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.21). Affected versions of the module insufficiently enforce signature validaโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 3:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-8964 - code-projects Hostel Management System Login hostel_manage.exe improper authentication

A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file hostel_manage.exe of the component Login. The manipulation leads to improper authentication. It is possible to launch the attack on the local host. The exploit has been disclosed tโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: Aug. 19, 2025, 7:09 p.m.

7.3

CVSS4.0

CVE-2025-7971 - Studio 5000 Logix Designerยฎ โ€“ Arbitrary Code Execution Vulnerability

A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicious code without triggering a crash.

๐Ÿ“… Published: Aug. 14, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-8875 - Insecure Deserialization Vulnerability

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

๐Ÿ“… Published: Aug. 14, 2025, 2:56 p.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 2:58 p.m.
Total resulsts: 349182
Page 4275 of 34,919
ยซ previous page ยป next page
Filters