9.3

CVSS4.0

CVE-2025-7918 - Simopro Technology|WinMatrix3 Web package - SQL Injection

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: July 21, 2025, 6:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-7917 - Simopro Technology|WinMatrix3 Web package - Arbitrary File Upload

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

📅 Published: July 21, 2025, 6:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-7916 - Simopro Technology|WinMatrix3 - Insecure Deserialization

WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.

📅 Published: July 21, 2025, 5:57 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7915 - Chanjet CRM Login Page mailinactive.php sql injection

A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of the component Login Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed …

📅 Published: July 21, 2025, 12:32 a.m. 🔄 Last Modified: Dec. 3, 2025, 2:52 p.m.

8.7

CVSS4.0

CVE-2025-7914 - Tenda AC6 httpd setparentcontrolinfo buffer overflow

A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow. The attack can be launched remotely.

📅 Published: July 21, 2025, 12:02 a.m. 🔄 Last Modified: July 23, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2020-26799 -

A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.

📅 Published: July 21, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2025-52374 -

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

📅 Published: July 21, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 6 p.m.

6.5

CVSS3.1

CVE-2025-51403 -

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

📅 Published: July 21, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 1:27 a.m.

5.4

CVSS3.1

CVE-2025-51397 -

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.

📅 Published: July 21, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 1:23 a.m.

5.4

CVSS3.1

CVE-2025-51396 -

A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.

📅 Published: July 21, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 1:22 a.m.
Total resulsts: 346622
Page 4321 of 34,663
« previous page » next page
Filters