7.3

CVSS3.1

CVE-2025-36460 - Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabil…

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An a…

📅 Published: Nov. 17, 2025, 10:47 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:56 p.m.

8.8

CVSS3.1

CVE-2025-32089 - Dell ControlVault3 CvManager_SBI buffer overflow vulnerability

A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vul…

📅 Published: Nov. 17, 2025, 10:34 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-13304 - D-Link DWR-M920/DWR-M921/DWR-M960/DWR-M961/DIR-825M formPingDiagnosticRun buffer overflow

A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated r…

📅 Published: Nov. 17, 2025, 10:32 p.m. 🔄 Last Modified: Dec. 8, 2025, 2:12 p.m.

5.4

CVSS3.1

CVE-2025-7711 - Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscribe…

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before run…

📅 Published: Nov. 17, 2025, 10:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

8.8

CVSS3.1

CVE-2025-36553 - Dell ControlVault3 CvManager buffer overflow vulnerability

A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability.

📅 Published: Nov. 17, 2025, 10:26 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:56 p.m.

5.3

CVSS4.0

CVE-2025-13303 - code-projects Courier Management System search-edit.php sql injection

A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Consignment causes sql injection. The attack can be initiated remotely. The exploit has been publicly d…

📅 Published: Nov. 17, 2025, 10:02 p.m. 🔄 Last Modified: Nov. 19, 2025, 1:05 p.m.

5.3

CVSS3.1

CVE-2025-64766 - NixOS has hardcoded credentials in Onlyoffice module

NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect …

📅 Published: Nov. 17, 2025, 9:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-13302 - code-projects Courier Management System add-new-officer.php sql injection

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be use…

📅 Published: Nov. 17, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 19, 2025, 1:05 p.m.

6.9

CVSS4.0

CVE-2025-13301 - itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection

A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The manipulation results in sql injection. It is possible to launch the attack remotely. The exploit has bee…

📅 Published: Nov. 17, 2025, 9:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 6:34 a.m.

7.5

CVSS3.1

CVE-2025-36118 - IBM Storage Virtualize Information Disclosure

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

📅 Published: Nov. 17, 2025, 8:47 p.m. 🔄 Last Modified: Dec. 8, 2025, 3:14 p.m.
Total resulsts: 346556
Page 2727 of 34,656
« previous page » next page
Filters