7.2

CVSS4.0

CVE-2025-14850 - Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted Directory

Advantech WebAccess/SCADAΒ is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

πŸ“… Published: Dec. 18, 2025, 8:30 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 7:44 p.m.

7.3

CVSS4.0

CVE-2025-13911 - Inductive Automation Ignition Execution with Unnecessary Privileges

The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The vulnerability arises from the absence of proper security controls that restrict which Python libraries can be imported and executed within the scripting environment. The core is…

πŸ“… Published: Dec. 18, 2025, 8:24 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

5.3

CVSS4.0

CVE-2025-14889 - Campcodes Advanced Voting Management System Password voters_edit.php improper authorization

A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is pos…

πŸ“… Published: Dec. 18, 2025, 8:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:54 a.m.

8.4

CVSS4.0

CVE-2023-53940 - Codigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown File

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file…

πŸ“… Published: Dec. 18, 2025, 7:57 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

8.5

CVSS4.0

CVE-2023-53937 - Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application sta…

πŸ“… Published: Dec. 18, 2025, 7:57 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

5.1

CVSS4.0

CVE-2024-58323 - Kentico Xperience <= 13.0.158 Checkbox Form Component Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 2:09 p.m.

5.1

CVSS4.0

CVE-2024-58322 - Kentico Xperience <= 13.0.158 Shipping Options Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 2:09 p.m.

5.1

CVSS4.0

CVE-2024-58321 - Kentico Xperience <= 13.0.159 Form Validation Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 2:09 p.m.

6.9

CVSS4.0

CVE-2024-58320 - Kentico Xperience <= 13.0.159 Authentication Information Disclosure

An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal netwo…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 4:39 p.m.

5.1

CVSS4.0

CVE-2024-58319 - Kentico Xperience <= 13.0.160 Pages Dashboard Widget Reflected XSS

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 2:09 p.m.
Total resulsts: 343919
Page 1982 of 34,392
Β« previous page Β» next page
Filters