6.9

CVSS4.0

CVE-2025-7915 - Chanjet CRM Login Page mailinactive.php sql injection

A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of the component Login Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed โ€ฆ

๐Ÿ“… Published: July 21, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 2:52 p.m.

8.7

CVSS4.0

CVE-2025-7914 - Tenda AC6 httpd setparentcontrolinfo buffer overflow

A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow. The attack can be launched remotely.

๐Ÿ“… Published: July 21, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: July 23, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2020-26799 -

A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2025-52374 -

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 6 p.m.

6.5

CVSS3.1

CVE-2025-51403 -

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:27 a.m.

5.4

CVSS3.1

CVE-2025-51397 -

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:23 a.m.

5.4

CVSS3.1

CVE-2025-51396 -

A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:22 a.m.

4.3

CVSS3.1

CVE-2025-43977 -

The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 6:14 p.m.

3.7

CVSS3.1

CVE-2025-54352 -

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-51401 -

A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:25 a.m.
Total resulsts: 349182
Page 4577 of 34,919
ยซ previous page ยป next page
Filters