5.1

CVSS4.0

CVE-2025-12873 - Campcodes School File Management update_user.php sql injection

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to th…

πŸ“… Published: Nov. 7, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.8

CVSS3.1

CVE-2025-9458 - PRT File Parsing Memory Corruption Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: Nov. 7, 2025, 6:01 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-64430 - Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File w…

πŸ“… Published: Nov. 7, 2025, 5:55 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-64347 - Apollo Router Improperly Enforces Renamed Access Control Directives

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes,…

πŸ“… Published: Nov. 7, 2025, 5:47 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS4.0

CVE-2025-12862 - projectworlds Online Notes Sharing Platform userprofile.php unrestricted upload

A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit …

πŸ“… Published: Nov. 7, 2025, 4:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

9.3

CVSS4.0

CVE-2025-3222 - Smallworld SWMFS Improper Authentication

Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.

πŸ“… Published: Nov. 7, 2025, 4:28 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS4.0

CVE-2025-7719 - Smallworld SWMFS Arbitrary File Ops

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions.

πŸ“… Published: Nov. 7, 2025, 4:28 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12861 - DedeBIZ spec_add.php sql injection

A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclos…

πŸ“… Published: Nov. 7, 2025, 4:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS4.0

CVE-2025-47207 - File Station 5

A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Stati…

πŸ“… Published: Nov. 7, 2025, 3:16 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

9.5

CVSS4.0

CVE-2025-52425 - QuMagie

An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later

πŸ“… Published: Nov. 7, 2025, 3:15 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318270
Page 92 of 31,827
Β« previous page Β» next page
Filters