2.3

CVSS3.1

CVE-2025-46643 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overf…

πŸ“… Published: Jan. 9, 2026, 4:07 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:38 p.m.

5.3

CVSS4.0

CVE-2025-15492 - RainyGao DocSys GroupMemberMapper.xml sql injection

A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a manipulation of the argument searchWord results in sql injection. It is possible to initiate the attack remotely. The …

πŸ“… Published: Jan. 9, 2026, 4:02 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:16 p.m.

5.3

CVSS3.1

CVE-2026-0817 - CampaignEvents API missing authorization exposes meeting and chat URLs

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, 3:50 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:15 p.m.

2.7

CVSS3.1

CVE-2025-46676 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive …

πŸ“… Published: Jan. 9, 2026, 3:48 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 4:16 p.m.

5.3

CVSS4.0

CVE-2026-0803 - PHPGurukul Online Course Registration System enroll.php sql injection

A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in sql injection. The attack may be launched remotely. The exp…

πŸ“… Published: Jan. 9, 2026, 3:32 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 4:24 p.m.

6

CVSS3.1

CVE-2025-46644 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization…

πŸ“… Published: Jan. 9, 2026, 3:31 p.m. πŸ”„ Last Modified: Jan. 10, 2026, 4:55 a.m.

9.8

CVSS3.1

CVE-2025-14598 - CVE-2025-14598

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

πŸ“… Published: Jan. 9, 2026, 12:14 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 4:16 p.m.

8.6

CVSS4.0

CVE-2025-66052 - Command injection in Vivotek IP7137 cameras

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access …

πŸ“… Published: Jan. 9, 2026, 11:54 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

6.9

CVSS4.0

CVE-2025-66051 - Path traversal in Vivotek IP7137 cameras

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using aΒ direct HTTP request. Due toΒ CVE-2025-66050, a password for administration panel is not set by default. The vendor has …

πŸ“… Published: Jan. 9, 2026, 11:54 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

9.3

CVSS4.0

CVE-2025-66050 - No password set for administrative account in Vivotek IP7137 cameras

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions a…

πŸ“… Published: Jan. 9, 2026, 11:53 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.
Total resulsts: 327160
Page 27 of 32,716
Β« previous page Β» next page
Filters