5.4

CVSS3.1

CVE-2025-68643 -

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by e…

📅 Published: Feb. 5, 2026, midnight 🔄 Last Modified: Feb. 11, 2026, 9:16 p.m.

6.1

CVSS3.1

CVE-2025-70791 -

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue…

📅 Published: Feb. 5, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:56 p.m.

8.1

CVSS3.1

CVE-2025-68721 -

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the a…

📅 Published: Feb. 5, 2026, midnight 🔄 Last Modified: Feb. 13, 2026, 3:15 p.m.

6.1

CVSS3.1

CVE-2025-70792 -

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was rep…

📅 Published: Feb. 5, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:54 p.m.

5.3

CVSS4.0

CVE-2026-1896 - WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed…

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId leads to improper access…

📅 Published: Feb. 4, 2026, 11:32 p.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

8.2

CVSS3.1

CVE-2025-13192 - Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endp…

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic SQL Injection via the multiple REST API endpoints in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parame…

📅 Published: Feb. 4, 2026, 11:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25286 - _GCafé 3.0 - 'gbClienService' Unquoted Service Path

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with Loc…

📅 Published: Feb. 4, 2026, 11:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25283 - Shrew Soft VPN Client 2.2.2 - 'iked' Unquoted Service Path

Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.

📅 Published: Feb. 4, 2026, 11:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25288 - Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

📅 Published: Feb. 4, 2026, 11:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25287 - Adaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service Path

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ t…

📅 Published: Feb. 4, 2026, 11:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347986
Page 1673 of 34,799
« previous page » next page
Filters