8.4

CVSS4.0

CVE-2025-15069 - Privilege Escalation in Gmission Web FAX

Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1

πŸ“… Published: Dec. 29, 2025, 5:05 a.m. πŸ”„ Last Modified: Jan. 13, 2026, 5:16 a.m.

8.5

CVSS4.0

CVE-2025-15068 - Account Takeover in Gmission Web FAX

Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 before 3.0.1

πŸ“… Published: Dec. 29, 2025, 5:05 a.m. πŸ”„ Last Modified: Jan. 13, 2026, 5:16 a.m.

5.1

CVSS4.0

CVE-2025-15173 - SohuTV CacheCloud InstanceController.java advancedAnalysis cross site scripting

A weakness has been identified in SohuTV CacheCloud up to 3.2.0. Affected is the function advancedAnalysis of the file src/main/java/com/sohu/cache/web/controller/InstanceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit h…

πŸ“… Published: Dec. 29, 2025, 5:02 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 1:26 p.m.

5.1

CVSS4.0

CVE-2025-15172 - SohuTV CacheCloud RedisConfigTemplateController.java preview cross site scripting

A security flaw has been discovered in SohuTV CacheCloud up to 3.2.0. This impacts the function preview of the file src/main/java/com/sohu/cache/web/controller/RedisConfigTemplateController.java. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has …

πŸ“… Published: Dec. 29, 2025, 4:32 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 1:27 p.m.

5.1

CVSS4.0

CVE-2025-15171 - SohuTV CacheCloud ServerController.java index cross site scripting

A vulnerability was identified in SohuTV CacheCloud up to 3.2.0. This affects the function index of the file src/main/java/com/sohu/cache/web/controller/ServerController.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly avai…

πŸ“… Published: Dec. 29, 2025, 4:02 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 1:28 p.m.

5.3

CVSS4.0

CVE-2025-15170 - Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting

A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the atta…

πŸ“… Published: Dec. 29, 2025, 3:32 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 9:42 p.m.

5.1

CVSS4.0

CVE-2025-15169 - BiggiDroid Simple PHP CMS editsite.php sql injection

A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected by this issue is some unknown functionality of the file /admin/editsite.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available …

πŸ“… Published: Dec. 29, 2025, 3:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

6.9

CVSS4.0

CVE-2025-15168 - itsourcecode Student Management System statistical.php sql injection

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 29, 2025, 2:32 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:56 p.m.

10

CVSS3.1

CVE-2025-52691 - Upload Arbitrary Files

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

πŸ“… Published: Dec. 29, 2025, 2:15 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.9

CVSS4.0

CVE-2025-15167 - itsourcecode Online Cake Ordering System detailtransac.php sql injection

A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may …

πŸ“… Published: Dec. 29, 2025, 2:02 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.
Total resulsts: 345139
Page 1986 of 34,514
Β« previous page Β» next page
Filters