5.1

CVSS4.0

CVE-2025-7867 - Portabilis i-Educar Agenda agenda.php cross site scripting

A vulnerability has been found in Portabilis i-Educar 2.9.0/2.10.0. This vulnerability affects unknown code of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novo_titulo/novo_descricao leads to cross site scripting. It is possible to initiate the attaโ€ฆ

๐Ÿ“… Published: July 20, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Sept. 27, 2025, 12:28 a.m.

5.1

CVSS4.0

CVE-2025-7866 - Portabilis i-Educar Disabilities Module educar_deficiencia_lst.php cross site scripting

A vulnerability was found in Portabilis i-Educar 2.9.0. It has been rated as problematic. This issue affects some unknown processing of the file /intranet/educar_deficiencia_lst.php of the component Disabilities Module. The manipulation of the argument Deficiรชncia ou Transtorno leads to cross site โ€ฆ

๐Ÿ“… Published: July 20, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 2:42 p.m.

5.1

CVSS4.0

CVE-2025-7865 - thinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scripting

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of the file src/main/java/com/jeesite/common/codec/EncodeUtils.java of the component XSS Filter. The manipulation of the argument text leads to cross siโ€ฆ

๐Ÿ“… Published: July 20, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 5:23 p.m.

5.3

CVSS4.0

CVE-2025-7864 - thinkgem JeeSite FileUploadController.java upload unrestricted upload

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java. The manipulation leads to unrestricted upload. It is possible to initiate the attack remโ€ฆ

๐Ÿ“… Published: July 20, 2025, 2:44 a.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 5:25 p.m.

5.1

CVSS4.0

CVE-2025-7863 - thinkgem JeeSite ServletUtils.java redirectUrl

A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function redirectUrl of the file src/main/java/com/jeesite/common/web/http/ServletUtils.java. The manipulation of the argument url leads to open redirect. The attack may be launchโ€ฆ

๐Ÿ“… Published: July 20, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: July 22, 2025, 3:15 p.m.

6.9

CVSS4.0

CVE-2025-7862 - TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument telnet_enabled with the input 1 leads to misโ€ฆ

๐Ÿ“… Published: July 20, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: July 23, 2025, 4:27 p.m.

9.8

CVSS3.1

CVE-2025-53770 - Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnโ€ฆ

๐Ÿ“… Published: July 20, 2025, 1:06 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.9

CVSS4.0

CVE-2025-7861 - code-projects Church Donation System search.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has โ€ฆ

๐Ÿ“… Published: July 20, 2025, 1:03 a.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:41 p.m.

6.9

CVSS4.0

CVE-2025-7860 - code-projects Church Donation System login_admin.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/login_admin.php. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. Theโ€ฆ

๐Ÿ“… Published: July 20, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:42 p.m.

6.9

CVSS4.0

CVE-2025-7859 - code-projects Church Donation System update_password_admin.php sql injection

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/update_password_admin.php. The manipulation of the argument new_password leads to sql injection. The attack can be initiated remotely. The exploโ€ฆ

๐Ÿ“… Published: July 20, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:42 p.m.
Total resulsts: 349182
Page 4586 of 34,919
ยซ previous page ยป next page
Filters