7.8

CVSS3.1

CVE-2025-53919 -

An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could potentially exploit this, leading to elevation…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:55 p.m.

9.8

CVSS3.1

CVE-2025-67791 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

6.2

CVSS3.1

CVE-2025-67174 -

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:19 p.m.

7.8

CVSS3.1

CVE-2025-53398 -

The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:58 p.m.

9.8

CVSS3.1

CVE-2022-23851 -

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 3:17 p.m.

6.1

CVSS3.1

CVE-2025-65233 -

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:26 p.m.

6.1

CVSS3.1

CVE-2025-67170 -

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

9.8

CVSS3.1

CVE-2025-67790 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

7.3

CVSS3.1

CVE-2025-67285 -

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleanin…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:46 p.m.

6.8

CVSS3.1

CVE-2025-67173 -

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.
Total resulsts: 342307
Page 1872 of 34,231
Β« previous page Β» next page
Filters