0.0

CVE-2025-27216 -

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate privileges.

๐Ÿ“… Published: Aug. 21, 2025, 12:01 a.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27217 -

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.

๐Ÿ“… Published: Aug. 21, 2025, 12:01 a.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-55524 -

Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 5:11 p.m.

0.0

CVE-2025-55523 -

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 5:10 p.m.

0.0

CVE-2025-47184 -

An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 7.0.1p02 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 12:52 p.m.

0.0

CVE-2025-51818 -

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 1:28 p.m.

0.0

CVE-2025-55383 -

Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the target server.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 2:50 p.m.

0.0

CVE-2025-55370 -

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 2 p.m.

0.0

CVE-2025-55521 -

An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via a crafted POST request.

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 5:06 p.m.

0.0

CVE-2024-45438 -

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email โ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 4:20 p.m.
Total resulsts: 306540
Page 11 of 30,654
ยซ previous page ยป next page
Filters