9.3

CVSS4.0

CVE-2023-53948 - Lilac-Reloaded for Nagios 2.0.8 Remote Code Execution via Autodiscovery

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST requestโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 9:05 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.5

CVSS4.0

CVE-2023-53947 - OCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege Escalation

OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.

๐Ÿ“… Published: Dec. 19, 2025, 9:05 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.5

CVSS4.0

CVE-2023-53946 - Arcsoft PhotoStudio 6.0.0.172 Unquoted Service Path Privilege Escalation

Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permiโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 9:05 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.7

CVSS4.0

CVE-2023-53945 - BrainyCP 1.0 Remote Code Execution via Authenticated Crontab Manipulation

BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a malicious command that spawns a reverse shell to a specified IP andโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 9:05 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

5.9

CVSS3.1

CVE-2025-68481 - FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow.โ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 8:14 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:14 p.m.

4.7

CVSS3.1

CVE-2025-67712 - HTML injection issue in ArcGIS Web App Builder

There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript executioโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 8:05 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-14968 - code-projects Simple Stock System update.php sql injection

A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /market/update.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been released to tโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:15 p.m.

6.3

CVSS4.0

CVE-2025-12874 - HTTP Request Smuggling in Quest Coexistence Manager for Notes

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an attacker toย bypass acโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 7:36 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-14967 - itsourcecode Student Management System candidates_report.php sql injection

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /candidates_report.php. The manipulation of the argument school_year leads to sql injection. The attack can be initiated remotely. The exploit is publโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:15 p.m.

5.1

CVSS4.0

CVE-2025-14966 - FastAdmin Backend Controller Backend.php selectpage sql injection

A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing manipulation of the argument custom/searchField can lead to sql injection. It is possible to lauโ€ฆ

๐Ÿ“… Published: Dec. 19, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 8:15 p.m.
Total resulsts: 323547
Page 7 of 32,355
ยซ previous page ยป next page
Filters