7

CVSS4.0

CVE-2025-64770 - Missing Authentication for ONVIF in iCam Cameras

The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

πŸ“… Published: Nov. 20, 2025, 8:25 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

4.8

CVSS4.0

CVE-2025-35029 - Medical Informatics Engineering Enterprise Health stored cross site scripting via Demographic Infor…

Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 202…

πŸ“… Published: Nov. 20, 2025, 7:34 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

8.7

CVSS3.0

CVE-2025-52668 -

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

8.8

CVSS3.0

CVE-2025-48986 -

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.3

CVSS3.0

CVE-2025-48987 -

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

3.5

CVSS3.0

CVE-2025-55123 -

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

4.3

CVSS3.0

CVE-2025-52671 -

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

2.7

CVSS3.0

CVE-2025-52666 -

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

4.3

CVSS3.0

CVE-2025-52669 -

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.1

CVSS3.0

CVE-2025-55124 -

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319172
Page 23 of 31,918
Β« previous page Β» next page
Filters