4.1

CVSS3.1

CVE-2025-63420 -

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63717 -

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attacke…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

10

CVSS3.1

CVE-2025-63689 -

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-63784 -

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing a…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-63686 -

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2025-60574 -

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63543 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-57698 -

AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the valid…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

9.6

CVSS3.1

CVE-2025-63691 -

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63544 -

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318119
Page 83 of 31,812
Β« previous page Β» next page
Filters