CVE-2025-52122 – CraftCMS Freeform SSTI Vulnerability
The following table lists the changes that have been made to the CVE-2025-52122 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-50989 – OPNsense Authenticated Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-50989 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-50986 – Diskover-web Stored Cross-Site Scripting Vulnerabilities
diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE, ES_TRANSLOGSYNCINT, EXCLUDES_FILES, FILE_TYPES[], INCLUDES_DIRS, INCLUDES_FILES, and TIMEZONE do not properly sanitize user-supplied input. Malicious payloads submitted via these parameters are persisted in the application and executed whenever an […]
CVE-2025-50985 – Diskover-web Community Edition Cross-Site Scripting (XSS)
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML response, allowing attackers to inject and execute arbitrary JavaScript when a victim visits a maliciously crafted URL.
CVE-2025-50972 – AbanteCart SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-50972 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-9532 – Portabilis i-Educar SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-9532 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-9531 – Portabilis i-Educar Agenda Module SQL Injection
The following table lists the changes that have been made to the CVE-2025-9531 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-9529 – Campcodes Payroll Management System Remote File Inclusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-9529 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-9528 – Linksys E1700 OS Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-9528 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]
CVE-2025-9527 – Linksys E1700 Stack-Based Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-9527 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 27, 2025 Action […]