8.7

CVSS4.0

CVE-2025-14572 - UTT 进取 512W formWebAuthGlobalConfig memory corruption

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAuthGlobalConfig. Performing manipulation of the argument hidcontact results in memory corruption. Remote exploitation of the attack is possible. The exploit has been made public and…

📅 Published: Dec. 12, 2025, 7:32 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:32 p.m.

8.6

CVSS3.1

CVE-2025-8083 - Vuetify Prototype Pollution via Preset options

The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html  due to the internal 'mergeDeep' utility function used to merge options wit…

📅 Published: Dec. 12, 2025, 7:29 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:29 p.m.

0.0

CVE-2025-14373 -

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

📅 Published: Dec. 12, 2025, 7:20 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:20 p.m.

0.0

CVE-2025-14372 -

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

📅 Published: Dec. 12, 2025, 7:20 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:20 p.m.

0.0

CVE-2025-14174 -

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

📅 Published: Dec. 12, 2025, 7:20 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:20 p.m.

6.3

CVSS3.1

CVE-2025-8082 - Vuetify XSS via unsanitized 'titleDateFormat' in 'VDatePicker'

Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the 'title-date-format' pro…

📅 Published: Dec. 12, 2025, 6:33 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:33 p.m.

6.9

CVSS4.0

CVE-2025-14571 - projectworlds Advanced Library Management System borrow_book.php sql injection

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be launched remotely. The exploit has been …

📅 Published: Dec. 12, 2025, 6:32 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:16 p.m.

6.9

CVSS4.0

CVE-2025-14570 - projectworlds Advanced Library Management System view_admin.php sql injection

A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been publishe…

📅 Published: Dec. 12, 2025, 6:32 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:16 p.m.

4.8

CVSS4.0

CVE-2025-14569 - ggml-org whisper.cpp common-whisper.cpp read_audio_data use after free

A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project w…

📅 Published: Dec. 12, 2025, 6:02 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:22 p.m.

5.3

CVSS4.0

CVE-2025-14568 - haxxorsid Stock-Management-System User.php sql injection

A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This impacts an unknown function of the file model/User.php. The manipulation of the argument employee_id/id/admin leads to sql injection. The attack can be initiated remo…

📅 Published: Dec. 12, 2025, 6:02 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:16 p.m.
Total resulsts: 322114
Page 7 of 32,212
« previous page » next page
Filters