8

CVSS3.1

CVE-2025-50849 -

CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the server side. An authenticated user can manipul…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 4, 2025, 9:13 a.m.

6.1

CVSS3.1

CVE-2025-50848 -

A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious con…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:35 p.m.

6.5

CVSS3.1

CVE-2025-50847 -

Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:36 p.m.

7.3

CVSS3.1

CVE-2025-45769 -

php-jwt v6.11.0 was discovered to contain weak encryption.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 4, 2025, 3:06 p.m.

6.1

CVSS3.1

CVE-2025-51569 -

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers t…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: July 31, 2025, 8:56 p.m.

6.1

CVSS3.1

CVE-2025-50270 -

A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: July 31, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2024-34327 -

Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:20 p.m.

7.6

CVSS3.1

CVE-2025-52203 -

A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are …

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:18 p.m.

6.5

CVSS3.1

CVE-2025-50867 -

A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:33 p.m.

8

CVSS3.1

CVE-2025-52289 -

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:37 p.m.
Total resulsts: 304580
Page 81 of 30,458
Β« previous page Β» next page
Filters