8.8

CVSS3.1

CVE-2025-64655 - Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: Nov. 20, 2025, 10:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

8.8

CVSS3.1

CVE-2025-36072 - IBM webMethods Integration Deserialization

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.

πŸ“… Published: Nov. 20, 2025, 10:09 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 2:44 p.m.

7.5

CVSS4.0

CVE-2025-13087 - Command Injection in Opto22 Groov REST API

A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When a POST request is executed against the vulnerable endpoint, the application reads certain header details and unsafely uses these values to build…

πŸ“… Published: Nov. 20, 2025, 9:32 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:09 a.m.

6.1

CVSS3.1

CVE-2025-36153 - IBM Concert Cross-Site Scripting

IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Nov. 20, 2025, 9:21 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:50 p.m.

5.1

CVSS3.1

CVE-2025-36158 - IBM Concert Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

πŸ“… Published: Nov. 20, 2025, 9:19 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:50 p.m.

6.2

CVSS3.1

CVE-2025-36159 - IBM Concert Improper Log Neutralization

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

πŸ“… Published: Nov. 20, 2025, 9:17 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:49 p.m.

5.3

CVSS3.1

CVE-2025-36160 - IBM Concert Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

πŸ“… Published: Nov. 20, 2025, 9:15 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:46 p.m.

7

CVSS4.0

CVE-2025-62674 - Missing Authentication for RTSP in iCam Cameras

The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

πŸ“… Published: Nov. 20, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:09 a.m.

7

CVSS4.0

CVE-2025-64770 - Missing Authentication for ONVIF in iCam Cameras

The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

πŸ“… Published: Nov. 20, 2025, 8:25 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:09 a.m.

4.8

CVSS4.0

CVE-2025-35029 - Medical Informatics Engineering Enterprise Health stored cross site scripting via Demographic Infor…

Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 202…

πŸ“… Published: Nov. 20, 2025, 7:34 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:51 p.m.
Total resulsts: 342358
Page 2266 of 34,236
Β« previous page Β» next page
Filters