7

CVSS4.0

CVE-2025-34410 - 1Panel CSRF in Change Username Functionality Allows Account Lockout

1Panel versions 1.10.33 -Β 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as anti-CSRF tokens or Origin/Referer validation. An attacker ca…

πŸ“… Published: Dec. 10, 2025, 4:07 p.m. πŸ”„ Last Modified: March 5, 2026, 12:04 p.m.

8.7

CVSS4.0

CVE-2025-34395 - Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by…

πŸ“… Published: Dec. 10, 2025, 3:45 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

10

CVSS4.0

CVE-2025-34394 - Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code execution.

πŸ“… Published: Dec. 10, 2025, 3:45 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

10

CVSS4.0

CVE-2025-34393 - Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserial…

πŸ“… Published: Dec. 10, 2025, 3:45 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

10

CVSS4.0

CVE-2025-34392 - Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.

πŸ“… Published: Dec. 10, 2025, 3:44 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

4.3

CVSS3.1

CVE-2025-13125 - IDOR in Im Park's DijiDemi

Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers.This issue affects DijiDemi: through 28.11.2025.

πŸ“… Published: Dec. 10, 2025, 2:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-13155 -

An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

πŸ“… Published: Dec. 10, 2025, 2:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-13152 -

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

πŸ“… Published: Dec. 10, 2025, 2:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-12046 -

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

πŸ“… Published: Dec. 10, 2025, 2:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-13127 - XSS in TACAS Consulting's GoldenHorn

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS).This issue affects GoldenHorn: before 4.25.1121.1.

πŸ“… Published: Dec. 10, 2025, 1:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347632
Page 2535 of 34,764
Β« previous page Β» next page
Filters