2.3

CVSS4.0

CVE-2026-2756 - OmniPEMF NeoRhythm BLE missing authentication

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high comple…

📅 Published: March 21, 2026, 5:32 p.m. 🔄 Last Modified: March 21, 2026, 5:32 p.m.

7.1

CVSS4.0

CVE-2019-25582 - i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameter

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.in…

📅 Published: March 21, 2026, 3:30 p.m. 🔄 Last Modified: March 21, 2026, 3:30 p.m.

8.8

CVSS4.0

CVE-2019-25581 - i-doit CMDB 1.12 SQL Injection via objGroupID Parameter

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive da…

📅 Published: March 21, 2026, 3:30 p.m. 🔄 Last Modified: March 21, 2026, 3:30 p.m.

8.8

CVSS4.0

CVE-2019-25580 - ownDMS 4.7 SQL Injection via pdfstream.php imagestream.php

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the I…

📅 Published: March 21, 2026, 3:30 p.m. 🔄 Last Modified: March 21, 2026, 3:30 p.m.

8.7

CVSS4.0

CVE-2019-25579 - phpTransformer 2016.9 Directory Traversal via jQueryFileUpload

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and re…

📅 Published: March 21, 2026, 3:30 p.m. 🔄 Last Modified: March 21, 2026, 3:30 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here