8.5

CVSS4.0

CVE-2025-59093 - Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300

Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to …

📅 Published: Jan. 26, 2026, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-59092 - Unauthenticated RPC Service in dormakaba Kaba exos 9300

An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status information about the Access Managers. Interacting with the servic…

📅 Published: Jan. 26, 2026, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-59091 - Hardcoded Legacy Accounts Allowing Control Over Access Managers in dormakaba Kaba exos 9300

Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visual…

📅 Published: Jan. 26, 2026, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-59090 - Unauthenticated SOAP API in dormakaba Kaba exos 9300

On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled c…

📅 Published: Jan. 26, 2026, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-27821 - HDFS native client: Out of bounds write in URI parser of native HDFS client

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

📅 Published: Jan. 26, 2026, 9:44 a.m. 🔄 Last Modified: Jan. 27, 2026, 8:30 p.m.

5.1

CVSS4.0

CVE-2025-41083 - Improper Neutralization in Altitude Communication Server

Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious web…

📅 Published: Jan. 26, 2026, 9:42 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2026-24656 - Apache Karaf: Decanter log-socket collector has deserialization vulnerability

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to…

📅 Published: Jan. 26, 2026, 9:41 a.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

6.9

CVSS4.0

CVE-2025-41082 - HTTP Request/Response Smuggling in Altitude Communication Server

Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which…

📅 Published: Jan. 26, 2026, 9:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2026-1429 - WellChoose|Single Sign-On Portal System - Reflected Cross-site Scripting

Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

📅 Published: Jan. 26, 2026, 8:20 a.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

8.7

CVSS4.0

CVE-2026-1428 - WellChoose|Single Sign-On Portal System - OS Command Injection

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

📅 Published: Jan. 26, 2026, 8:14 a.m. 🔄 Last Modified: April 18, 2026, 7 p.m.
Total resulsts: 349182
Page 1950 of 34,919
« previous page » next page
Filters