5.5

CVSS3.1

CVE-2025-12748 - Libvirt: denial of service in xml parsing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too m…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 2:40 p.m.

0.0

CVE-2025-63713 -

Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary web script or HTML via crafted input in the custom test creation feature. The vulnerability exists because the application fails to properly sanitize user-supplied input in test …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-60574 -

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

9.6

CVSS3.1

CVE-2025-63691 -

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63543 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.1

CVSS3.1

CVE-2025-63785 -

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a text element. An atta…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63716 -

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63639 -

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing th…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

10

CVSS3.1

CVE-2025-63689 -

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63544 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318281
Page 100 of 31,829
Β« previous page Β» next page
Filters