Filter and search through 196,409 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2025-41070 | Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victi... | 0.0 | 0 | Neutral | No |
| No |
| CVE-2025-4107 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41069 | Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41065 | Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in th... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41064 | Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method. | 0.0 | 0 | Neutral | No | No |
| CVE-2025-4106 | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by up... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41031 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a PO... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41030 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET ‘... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41028 | A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and de... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-4102025 | No description available | 0.0 | 0 | Neutral | Yes | No |
| CVE-2025-41019 | SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' pa... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41017 | Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from securi... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41016 | Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm e... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41010 | Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-dom... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41009 | SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data fr... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41006 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41005 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’. | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41004 | Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ ... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41003 | Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_p... | 0.0 | 0 | Neutral | No | No |
| CVE-2025-41000 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy ... | 0.0 | 0 | Neutral | No | No |