10

CVSS4.0

CVE-2025-12176 - Undocumented Administrative Accounts

Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 24, 2025, 3:56 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 3:05 p.m.

8.7

CVSS4.0

CVE-2025-62714 - Karmada Dashboard API Unauthorized Access Vulnerability

Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not en…

πŸ“… Published: Oct. 24, 2025, 3:41 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 10:10 p.m.

7.5

CVSS3.1

CVE-2025-11145 - User Enumeration in CBK Soft's enVision

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting.This issue affec…

πŸ“… Published: Oct. 24, 2025, 2:25 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 11:33 a.m.

9.3

CVSS4.0

CVE-2025-8536 - SQL Injection in DobryCMS

A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into language functionality allows for SQL Injection attacks. This issue affects older branches of this software.

πŸ“… Published: Oct. 24, 2025, 2:18 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 10:10 p.m.

8.6

CVSS3.1

CVE-2025-43994 -

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: Oct. 24, 2025, 2:14 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 2:31 p.m.

9.8

CVSS3.1

CVE-2025-43995 -

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An u…

πŸ“… Published: Oct. 24, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-46425 -

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

πŸ“… Published: Oct. 24, 2025, 2:04 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

0.0

CVE-2025-12152 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Oct. 24, 2025, 12:53 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:15 p.m.

4.3

CVSS3.1

CVE-2025-11576 - AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated …

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This makes it possible for una…

πŸ“… Published: Oct. 24, 2025, 12:29 p.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.

7.5

CVSS3.1

CVE-2025-10861 - Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers …

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4. This is due to insufficient validation on the URLs supplied via the URL parameter. Th…

πŸ“… Published: Oct. 24, 2025, 11:25 a.m. πŸ”„ Last Modified: April 8, 2026, 4:56 p.m.
Total resulsts: 343968
Page 2768 of 34,397
Β« previous page Β» next page
Filters