5.1

CVSS4.0

CVE-2026-0580 - SourceCodester API Key Manager App Import Key cross site scripting

A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.

πŸ“… Published: Jan. 5, 2026, 7:32 a.m. πŸ”„ Last Modified: April 18, 2026, 8:30 a.m.

7.1

CVSS4.0

CVE-2025-15235 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Missing Authorization

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files.

πŸ“… Published: Jan. 5, 2026, 7:25 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:12 p.m.

8.7

CVSS4.0

CVE-2025-15462 - UTT 进取 520W ConfigAdvideo strcpy buffer overflow

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public …

πŸ“… Published: Jan. 5, 2026, 7:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:18 a.m.

8.7

CVSS4.0

CVE-2025-15461 - UTT 进取 520W formTaskEdit strcpy buffer overflow

A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. …

πŸ“… Published: Jan. 5, 2026, 6:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:18 a.m.

8.7

CVSS4.0

CVE-2025-15460 - UTT 进取 520W formPptpClientConfig strcpy buffer overflow

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may …

πŸ“… Published: Jan. 5, 2026, 6:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:18 a.m.

3.5

CVSS3.1

CVE-2025-9543 - FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS

The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

πŸ“… Published: Jan. 5, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-14124 - Team < 5.0.11 - Unauthenticated SQLi

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

πŸ“… Published: Jan. 5, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-15459 - UTT 进取 520W formUser strcpy buffer overflow

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formUser. Such manipulation of the argument passwd1 leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and ma…

πŸ“… Published: Jan. 5, 2026, 5:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:17 a.m.

6.9

CVSS4.0

CVE-2025-15458 - bg5sbk MiniCMS Article post-edit.php improper authentication

A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicl…

πŸ“… Published: Jan. 5, 2026, 5:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:17 a.m.

6.9

CVSS4.0

CVE-2025-15457 - bg5sbk MiniCMS Trash File Restore post.php improper authentication

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The ex…

πŸ“… Published: Jan. 5, 2026, 4:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:16 a.m.
Total resulsts: 347398
Page 2114 of 34,740
Β« previous page Β» next page
Filters