5.5

CVSS3.1

CVE-2025-35981 -

Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.…

πŸ“… Published: Oct. 23, 2025, 3:37 a.m. πŸ”„ Last Modified: Oct. 27, 2025, 1:20 p.m.

8.8

CVSS4.0

CVE-2025-11575 - MongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation dire…

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.

πŸ“… Published: Oct. 23, 2025, 12:22 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

4.3

CVSS3.1

CVE-2025-54966 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain situations, including local file paths and SOCET GXP version information.

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 4:19 p.m.

7.5

CVSS3.1

CVE-2025-50950 - audiofile: NULL pointer dereference in the ModuleState::setup function

Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 4:22 p.m.

6.1

CVSS3.1

CVE-2025-56008 -

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 1:09 p.m.

8.4

CVSS3.1

CVE-2025-54964 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is n…

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-54963 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job request that grants read access to files on the filesystem with the permissions of the GXP Job Service process. The path to a file is not sanitized for…

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 4:22 p.m.

6.1

CVSS3.1

CVE-2025-57240 -

Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute arbitrary code via the registration step.

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

7.1

CVSS3.1

CVE-2025-61132 -

A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NA…

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 1:20 p.m.

6.1

CVSS3.1

CVE-2025-61413 -

A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks.

πŸ“… Published: Oct. 23, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:35 a.m.
Total resulsts: 343923
Page 2781 of 34,393
Β« previous page Β» next page
Filters