5.3

CVSS4.0

CVE-2025-4260 - zhangyanbo2007 youkefu TemplateController.java impsave deserialization

A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launche…

πŸ“… Published: May 5, 2025, 2:31 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:29 p.m.

5.3

CVSS4.0

CVE-2025-4259 - newbee-mall UploadController.java upload unrestricted upload

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched rem…

πŸ“… Published: May 5, 2025, 2 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 7:09 p.m.

5.3

CVSS4.0

CVE-2025-4258 - zhangyanbo2007 youkefu MediaController.java upload unrestricted upload

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The manipulation of the argument imgFile leads to unrestricted upl…

πŸ“… Published: May 5, 2025, 1:31 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 5:33 p.m.

0.0

CVE-2025-4273 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: May 5, 2025, 1:20 a.m. πŸ”„ Last Modified: May 5, 2025, 3:15 a.m.

5.1

CVSS4.0

CVE-2025-4257 - SeaCMS admin_pay.php cross site scripting

A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…

πŸ“… Published: May 5, 2025, 1 a.m. πŸ”„ Last Modified: Oct. 6, 2025, 4:28 p.m.

5.1

CVSS4.0

CVE-2025-4256 - SeaCMS admin_paylog.php cross site scripting

A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: May 5, 2025, 12:31 a.m. πŸ”„ Last Modified: June 12, 2025, 7:22 p.m.

6.9

CVSS4.0

CVE-2025-4255 - PCMan FTP Server RMD Command buffer overflow

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 16, 2025, 5:43 p.m.

9.8

CVSS3.1

CVE-2025-45616 -

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 3:08 p.m.

9.8

CVSS3.1

CVE-2025-45611 -

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 8:50 p.m.

6.5

CVSS3.1

CVE-2025-45240 -

foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 5:44 p.m.
Total resulsts: 346624
Page 5299 of 34,663
Β« previous page Β» next page
Filters