9.1

CVSS3.1

CVE-2025-14265 - Improper server-side validation in ScreenConnect extension framework

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of cust…

📅 Published: Dec. 11, 2025, 2:21 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:21 p.m.

5.9

CVSS3.1

CVE-2024-40593 -

A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4…

📅 Published: Dec. 11, 2025, 2:10 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:14 a.m.

4.8

CVSS4.0

CVE-2025-14517 - Yalantis uCrop AndroidManifest.xml UCropActivity  improper export of android application components

A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only be executed locally. The exploit has been publicly disclosed a…

📅 Published: Dec. 11, 2025, 2:02 p.m. 🔄 Last Modified: March 5, 2026, 7:04 p.m.

5.3

CVSS4.0

CVE-2025-14516 - Yalantis uCrop URL com.yalantis.ucrop.task.BitmapLoadTask.java downloadFile server-side request for…

A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoadTask.java of the component URL Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. The exp…

📅 Published: Dec. 11, 2025, 2:02 p.m. 🔄 Last Modified: March 5, 2026, 7:02 p.m.

7.6

CVSS3.1

CVE-2025-13003 - IDOR in Aksis Computer's AxOnboard

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers.This issue affects AxOnboard: from 3.2.0 before 3.3.0.

📅 Published: Dec. 11, 2025, 12:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-14515 - Campcodes Supplier Management System add_unit.php sql injection

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argument txtunitDetails leads to sql injection. The attack can be launched remotely. The exploit has been …

📅 Published: Dec. 11, 2025, 12:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 5:45 a.m.

6.9

CVSS4.0

CVE-2025-14514 - Campcodes Supplier Management System add_distributor.php sql injection

A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be initiated remotely. The exploit has been published and may be us…

📅 Published: Dec. 11, 2025, 11:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 5:45 a.m.

6.5

CVSS3.1

CVE-2025-64995 - Privilege Escalation via Process Hijacking in 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting…

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the devic…

📅 Published: Dec. 11, 2025, 11:29 a.m. 🔄 Last Modified: Jan. 9, 2026, 2:02 a.m.

6.5

CVSS3.1

CVE-2025-64994 - Privilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate instruction

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate pri…

📅 Published: Dec. 11, 2025, 11:29 a.m. 🔄 Last Modified: Jan. 9, 2026, 2:04 a.m.

6.8

CVSS3.1

CVE-2025-64993 - Command Injection in 1E-ConfigMgrConsoleExtensions Instructions

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote exec…

📅 Published: Dec. 11, 2025, 11:29 a.m. 🔄 Last Modified: Jan. 9, 2026, 2:06 a.m.
Total resulsts: 346285
Page 2372 of 34,629
« previous page » next page
Filters