0.0

CVE-2025-66363 -

An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 3:55 p.m.

0.0

CVE-2021-35484 -

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive…

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 5:28 p.m.

0.0

CVE-2024-55019 -

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 6:32 p.m.

0.0

CVE-2026-26892 -

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 6:22 p.m.

0.0

CVE-2025-66945 -

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 6:06 p.m.

0.0

CVE-2025-52365 -

A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.system(). The vulnerability arises from improper input handling where command-line arguments are directly…

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 2:37 p.m.

7.2

CVSS3.1

CVE-2025-67840 -

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled parame…

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 5:54 p.m.

7.2

CVSS3.1

CVE-2025-63910 -

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 5:55 p.m.

8.8

CVSS3.1

CVE-2026-1566 - LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set …

πŸ“… Published: March 2, 2026, 11:22 p.m. πŸ”„ Last Modified: March 2, 2026, 11:22 p.m.

5.3

CVSS3.1

CVE-2026-1336 - AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 - Missing Authorization to Unauthenti…

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible fo…

πŸ“… Published: March 2, 2026, 11:22 p.m. πŸ”„ Last Modified: March 2, 2026, 11:22 p.m.
Total resulsts: 335584
Page 15 of 33,559
Β« previous page Β» next page
Filters