0.0

CVE-2025-63718 -

A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63717 -

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attacke…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63639 -

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing th…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63544 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-63686 -

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

5.4

CVSS3.1

CVE-2025-61261 -

A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.6

CVSS3.1

CVE-2025-63783 -

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user f…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

8.7

CVSS4.0

CVE-2025-58423 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

πŸ“… Published: Nov. 6, 2025, 10:31 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.7

CVSS4.0

CVE-2025-59171 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

πŸ“… Published: Nov. 6, 2025, 10:29 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:15 p.m.

8.7

CVSS4.0

CVE-2025-62630 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

πŸ“… Published: Nov. 6, 2025, 10:27 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:15 p.m.
Total resulsts: 318358
Page 108 of 31,836
Β« previous page Β» next page
Filters