6.9

CVSS4.0

CVE-2025-30062 - SQL injection in CheckUnitCodeAndKey.pl

In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.

📅 Published: March 2, 2026, 11:16 a.m. 🔄 Last Modified: March 3, 2026, 8:45 a.m.

9.4

CVSS4.0

CVE-2025-30044 - RCE on uhcapache user permissions

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl", the parameters are not sufficiently normalized, which enables code injection.

📅 Published: March 2, 2026, 11:15 a.m. 🔄 Last Modified: March 3, 2026, 8:45 a.m.

9

CVSS4.0

CVE-2025-30042 - Session generation possible with certificate number only

The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, rega…

📅 Published: March 2, 2026, 11:14 a.m. 🔄 Last Modified: March 9, 2026, 4:49 p.m.

9

CVSS4.0

CVE-2025-30035 - Lack of API authentication allowing session generation for any user

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the s…

📅 Published: March 2, 2026, 11:14 a.m. 🔄 Last Modified: March 3, 2026, 8:45 a.m.

6.1

CVSS3.1

CVE-2026-3441 - Binutils: gnu binutils: information disclosure via specially crafted xcoff object file

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw…

📅 Published: March 2, 2026, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 10:45 p.m.

6.1

CVSS3.1

CVE-2026-3442 - Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd l…

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lea…

📅 Published: March 2, 2026, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 10:45 p.m.

8.8

CVSS4.0

CVE-2025-10350 - SQL injection in CGM NETRAAD

SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.

📅 Published: March 2, 2026, 11:09 a.m. 🔄 Last Modified: March 3, 2026, 8:45 a.m.

9.3

CVSS4.0

CVE-2026-2584 - SQL Injection in Ciser System SL firmware

A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthenticated, remote attacker (AV:N/PR:N) can exploit this flaw by sending specially crafted SQL queries through the login interface. Due to low attack complexity (AC:L) and the absen…

📅 Published: March 2, 2026, 9:01 a.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

7.2

CVSS3.1

CVE-2026-20416 - Local Privilege Escalation via Out‑of‑Bounds Write in PCIe Driver on MediaTek Chipsets

In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315038 / ALPS10340155; Issue ID: MSV-5155.

📅 Published: March 2, 2026, 8:39 a.m. 🔄 Last Modified: April 16, 2026, 2:45 p.m.

4.4

CVSS3.1

CVE-2026-20445 - Race Condition in MediaTek MDDP Leading to Local Denial of Service

In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10289875; Issue ID: MSV-5184.

📅 Published: March 2, 2026, 8:39 a.m. 🔄 Last Modified: April 16, 2026, 2:45 p.m.
Total resulsts: 349182
Page 1385 of 34,919
« previous page » next page
Filters