5.3
CVE-2025-4260 - zhangyanbo2007 youkefu TemplateController.java impsave deserialization
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launcheβ¦
5.3
CVE-2025-4259 - newbee-mall UploadController.java upload unrestricted upload
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remβ¦
5.3
CVE-2025-4258 - zhangyanbo2007 youkefu MediaController.java upload unrestricted upload
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The manipulation of the argument imgFile leads to unrestricted uplβ¦
0.0
CVE-2025-4273 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.1
CVE-2025-4257 - SeaCMS admin_pay.php cross site scripting
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed toβ¦
5.1
CVE-2025-4256 - SeaCMS admin_paylog.php cross site scripting
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and mβ¦
6.9
CVE-2025-4255 - PCMan FTP Server RMD Command buffer overflow
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
9.8
CVE-2025-45616 -
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
9.8
CVE-2025-45611 -
Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.
6.5
CVE-2025-45240 -
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.