9.8

CVSS3.1

CVE-2025-26319 -

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:50 a.m.

7.2

CVSS3.1

CVE-2025-25426 -

yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 8:34 p.m.

9.8

CVSS3.1

CVE-2025-26136 -

A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:54 a.m.

10

CVSS3.1

CVE-2024-50704 -

Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 5:28 p.m.

7.8

CVSS3.1

CVE-2020-23438 -

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: March 26, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2025-26182 -

An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 3:30 p.m.

7.1

CVSS3.1

CVE-2024-50705 -

Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

๐Ÿ“… Published: March 4, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 3:42 p.m.

5.3

CVSS4.0

CVE-2025-1891 - shishuocms cross-site request forgery

A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 3, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-1890 - shishuocms ManageUpLoadAction.java handleRequest unrestricted upload

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be iโ€ฆ

๐Ÿ“… Published: March 3, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: March 5, 2025, 2:05 p.m.

2.3

CVSS4.0

CVE-2025-1882 - i-Drive i11/i12 Device Setting improper access control for register interface

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within โ€ฆ

๐Ÿ“… Published: March 3, 2025, 9 p.m. ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.
Total resulsts: 349182
Page 6469 of 34,919
ยซ previous page ยป next page
Filters