5.3

CVSS4.0

CVE-2025-14262 - Jobs can be saved as workflows with wrong permissions on KNIME Business Hub

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permi…

πŸ“… Published: Dec. 8, 2025, 9:34 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 3:38 a.m.

6.9

CVSS4.0

CVE-2025-14226 - itsourcecode Student Management System edit_user.php sql injection

A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and m…

πŸ“… Published: Dec. 8, 2025, 9:32 a.m. πŸ”„ Last Modified: Dec. 10, 2025, 5:42 p.m.

8.4

CVSS4.0

CVE-2025-66461 -

FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.

πŸ“… Published: Dec. 8, 2025, 9:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-27020 - Improper configuration of SSH service in Infinera MTC-9

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

πŸ“… Published: Dec. 8, 2025, 9:26 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:55 p.m.

9.8

CVSS3.1

CVE-2025-27019 - Remote shell service (RSH) in Infinera MTC-9

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

πŸ“… Published: Dec. 8, 2025, 9:22 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:55 p.m.

5.3

CVSS4.0

CVE-2025-14225 - D-Link DCS-930L alphapd setSystemAdmin command injection

A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed an…

πŸ“… Published: Dec. 8, 2025, 9:02 a.m. πŸ”„ Last Modified: Dec. 11, 2025, 12:07 a.m.

6.5

CVSS3.1

CVE-2025-26489 - Improper input validation in Netconf service in Infinera MTC-9

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

πŸ“… Published: Dec. 8, 2025, 8:56 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:55 p.m.

7.5

CVSS3.1

CVE-2025-26488 - Improper input validation in XML Management service in Infinera MTC-9

Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

πŸ“… Published: Dec. 8, 2025, 8:52 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:56 p.m.

8.6

CVSS3.1

CVE-2025-26487 - Server Side Request Forgery (SSRF) in the web server of Infinera MTC-9

Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.

πŸ“… Published: Dec. 8, 2025, 8:44 a.m. πŸ”„ Last Modified: Dec. 22, 2025, 6:56 p.m.

8.7

CVSS3.1

CVE-2025-12956 - Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovato…

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: Dec. 8, 2025, 8:38 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:49 p.m.
Total resulsts: 349182
Page 2777 of 34,919
Β« previous page Β» next page
Filters