Vulnerability DB Entries

Total CVEs
38
Disclosed
Affected Assets
599779
Digital assets impacted
Affected Users
1352257900
Users impacted
Elite Contributor
AlasdairGorniak
with 3 CVEs
Proficient Contributor
daeda1us
with 4 CVEs
Competent Contributor
0xhamy
with 28 CVEs
Title CVE ID Author Credit Severity Post Date Action
Vvveb - v1.0.5 - Cross-Site Scripting via SVG CVE-2025-8976 0xhamy High 2025-10-22
Vvveb - v1.0.5 - Cross-Site Scripting via navbar CVE-2025-8521 0xhamy High 2025-10-22
EasyAppointments - v1.5.0 - Password Brute Force CVE-2024-57602 0xhamy Critical 2025-10-22
EasyAppointments - v1.5.0 - Cross-Site Scripting CVE-2024-57601 0xhamy High 2025-10-22
OnlyOffice Community Server - v12.7.0 - Cross-Site Scripting (cross-origin) CVE-2025-10255 0xhamy,daeda1us Low 2025-10-22
OnlyOffice Community Server - v12.7.0 - Cross-Site Scripting CVE-2025-10254 0xhamy,daeda1us High 2025-10-22
Lemon OS - vnightly-2024-07-12 - Remote stack overflow CVE-2025-9001 0xhamy High 2025-10-22
Apache Answer - v1.4.1 - Externally referenced images can leak user privacy CVE-2025-29868 0xhamy,daeda1us Medium 2025-10-22
Mentingo - File Upload to XSS CVE-2025-10741 KhanMarshai Medium 2025-10-16
Frappe LMS - v2.35.0 - Improper Access Controls CVE-2025-11281 0xhamy,KhanMarshai Medium 2025-10-14
Frappe LMS - v2.35.0 - Improper Access Controls (unauthenticated) CVE-2025-11280 0xhamy,KhanMarshai High 2025-10-14
Frappe LMS - v2.35.0 - Cross-Site Scripting as student CVE-2025-11282 0xhamy,KhanMarshai High 2025-10-14
Frappe LMS - v2.35.0 - Cross-Site Scripting as instructor CVE-2025-11283 0xhamy,KhanMarshai Medium 2025-10-14
Typo3 CMS - v13.4.11 - Unrestricted File Upload CVE-2025-47939 0xhamy Medium 2025-09-29
NukeViet - v4.5.06 - Server Side Request Forgery CVE-2025-8772 0xhamy High 2025-09-29
Vvveb - v1.0.5 - Code Execution CVE-2025-8518 0xhamy Critical 2025-09-29
Vvveb - v1.0.5 - Server Side Request Forgery CVE-2025-8520 0xhamy Medium 2025-09-29
Vvveb - v1.0.5 - Internal File Read CVE-2025-8519 0xhamy Medium 2025-09-29
Fuel CMS - v1.5.2 - Cross-Site Scripting CVE-2024-57605 0xhamy High 2025-09-29
ezBookkeeping - v0.7.0 - Login Bruteforce CVE-2024-57603 0xhamy Critical 2025-09-29