7.2

CVSS4.0

CVE-2025-34248 - D-Link Nuclias Connect < v1.3.1.4 Directory Traversal to Arbitrary File Deletion

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity โ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 8:43 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-61602 - BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmojiId` in the GraphQL mutation `chatSendMessageReaโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:40 p.m.

6.9

CVSS4.0

CVE-2025-11556 - code-projects Simple Leave Manager user.php sql injection

A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

๐Ÿ“… Published: Oct. 9, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:32 p.m.

6.9

CVSS4.0

CVE-2025-11555 - Campcodes Online Learning Management System calendar_of_events.php sql injection

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start results in sql injection. The attack may be launched remotely. The exploit is now public and may be usโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:32 p.m.

7.5

CVSS3.1

CVE-2025-61601 - BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array โ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 8:29 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:29 p.m.

8.2

CVSS4.0

CVE-2025-35061 - Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServiโ€ฆ

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.

๐Ÿ“… Published: Oct. 9, 2025, 8:22 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:22 p.m.

6.9

CVSS4.0

CVE-2025-35062 - Newforma Info Exchange (NIX) default anonymous access

Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.

๐Ÿ“… Published: Oct. 9, 2025, 8:22 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:22 p.m.

5.1

CVSS4.0

CVE-2025-35060 - Newforma Info Exchange (NIX) stored XSS via SVG file upload

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.

๐Ÿ“… Published: Oct. 9, 2025, 8:22 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:22 p.m.

5.3

CVSS4.0

CVE-2025-35059 - Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspx

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

๐Ÿ“… Published: Oct. 9, 2025, 8:21 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:21 p.m.

8.2

CVSS4.0

CVE-2025-35058 - Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashx

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.

๐Ÿ“… Published: Oct. 9, 2025, 8:21 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:21 p.m.
Total resulsts: 313621
Page 11 of 31,363
ยซ previous page ยป next page
Filters