0.0
CVE-2025-25725 -
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25724. Reason: This candidate is a reservation duplicate of CVE-2025-25724. Notes: All CVE users should reference CVE-2025-25724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…
0.0
CVE-2025-25726 -
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a reservation duplicate of CVE-2024-53427. Notes: All CVE users should reference CVE-2024-53427 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…
5.4
CVE-2024-57278 -
A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing an attacker to inject malicious JavaScript payloads. When a victim accesses a crafted URL conta…
6.5
CVE-2024-57249 -
Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses t…
9.8
CVE-2024-55215 -
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
7.5
CVE-2024-55272 -
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.
8.7
CVE-2025-0675 - Elber Communications Equipment Hidden Functionality
Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
9.3
CVE-2025-0674 - Elber Communications Equipment Authentication Bypass Using an Alternate Path or Channel
Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthoriz…
5.3
CVE-2025-1084 - Mindskip xzs-mysql 学之思开源考试系统 cross-site request forgery
A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public a…
2.3
CVE-2025-1083 - Mindskip xzs-mysql 学之思开源考试系统 CORS cross-domain policy
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. …