6.5

CVSS3.1

CVE-2025-63687 -

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

4.1

CVSS3.1

CVE-2025-63420 -

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 9:45 p.m.

0.0

CVE-2025-63716 -

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-63784 -

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing a…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

0.0

CVE-2025-63638 -

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clic…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-60574 -

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 3:15 p.m.

9.6

CVSS3.1

CVE-2025-63691 -

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63640 -

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63713 -

Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary web script or HTML via crafted input in the custom test creation feature. The vulnerability exists because the application fails to properly sanitize user-supplied input in test …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63639 -

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing th…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318308
Page 102 of 31,831
Β« previous page Β» next page
Filters