5.1

CVSS3.1

CVE-2025-9612 - CVE-2025-9612

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical…

📅 Published: Dec. 9, 2025, 6:44 p.m. 🔄 Last Modified: Jan. 14, 2026, 5:43 p.m.

6.9

CVSS4.0

CVE-2025-14334 - itsourcecode Student Management System new_adviser.php sql injection

A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipulation of the argument Name can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

📅 Published: Dec. 9, 2025, 6:32 p.m. 🔄 Last Modified: Dec. 16, 2025, 8:09 p.m.

4.8

CVSS4.0

CVE-2025-11531 - HP System Event Utility and Omen Gaming Hub – Potential Arbitrary Code Execution

HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0.

📅 Published: Dec. 9, 2025, 6:29 p.m. 🔄 Last Modified: Jan. 21, 2026, 7:22 p.m.

9.3

CVSS4.0

CVE-2025-34414 - Entrust Instant Financial Issuance (IFI) Legacy Remoting Service .NET Remoting RCE

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel wit…

📅 Published: Dec. 9, 2025, 6:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-34413 - Legality WHISTLEBLOWING Missing Critical HTTP Security Headers

Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and Cros…

📅 Published: Dec. 9, 2025, 6:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-34396 - MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAINFY.DLL

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure search order. If the D…

📅 Published: Dec. 9, 2025, 6:11 p.m. 🔄 Last Modified: March 5, 2026, 12:03 p.m.

5.3

CVSS4.0

CVE-2025-34408 - MailEnable < 10.54 Reflected XSS in Added Parameter of MAI/AddRecipientsResult.aspx

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Added value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an atta…

📅 Published: Dec. 9, 2025, 6:10 p.m. 🔄 Last Modified: March 5, 2026, 12:04 p.m.

5.3

CVSS4.0

CVE-2025-34398 - MailEnable < 10.54 Reflected XSS in AddressesBcc Parameter of AddressBook.aspx

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesBcc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the …

📅 Published: Dec. 9, 2025, 6:10 p.m. 🔄 Last Modified: March 5, 2026, 12:04 p.m.

5.3

CVSS4.0

CVE-2025-34399 - MailEnable < 10.54 Reflected XSS in AddressesCc Parameter of AddressBook.aspx

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the Ja…

📅 Published: Dec. 9, 2025, 6:10 p.m. 🔄 Last Modified: March 5, 2026, 12:04 p.m.

5.3

CVSS4.0

CVE-2025-34400 - MailEnable < 10.54 Reflected XSS in AddressesTo Parameter of AddressBook.aspx

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the re…

📅 Published: Dec. 9, 2025, 6:09 p.m. 🔄 Last Modified: March 5, 2026, 12:04 p.m.
Total resulsts: 349182
Page 2705 of 34,919
« previous page » next page
Filters