6.3

CVSS3.1

CVE-2025-5343 - Stored XSS

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

πŸ“… Published: Oct. 30, 2025, 2:28 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:43 a.m.

7.8

CVSS3.1

CVE-2025-43942 -

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: Oct. 30, 2025, 2:23 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:14 a.m.

4.3

CVSS3.1

CVE-2025-5342 - Denial of Service (DoS)

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

πŸ“… Published: Oct. 30, 2025, 2:20 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:43 a.m.

7.8

CVSS3.1

CVE-2025-46422 -

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

πŸ“… Published: Oct. 30, 2025, 2:19 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:16 a.m.

7.8

CVSS3.1

CVE-2025-46423 -

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

πŸ“… Published: Oct. 30, 2025, 2:14 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:12 a.m.

9.8

CVSS3.1

CVE-2025-43027 -

A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative access to the Genetec Security Center system. The Genetec engineering team discovered this issue internally. There is currently no evidence that this v…

πŸ“… Published: Oct. 30, 2025, 2:12 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.8

CVSS3.1

CVE-2025-43939 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: Oct. 30, 2025, 2:10 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:57 p.m.

7.8

CVSS3.1

CVE-2025-43940 -

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: Oct. 30, 2025, 2:05 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:58 p.m.

7.2

CVSS3.1

CVE-2025-43941 -

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. T…

πŸ“… Published: Oct. 30, 2025, 1:57 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:58 p.m.

5.1

CVSS4.0

CVE-2025-10348 - Stored Cross-Site Scripting in URVE Smart Office

URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without a…

πŸ“… Published: Oct. 30, 2025, 1 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 10:14 a.m.
Total resulsts: 317435
Page 113 of 31,744
Β« previous page Β» next page
Filters