6.9

CVSS4.0

CVE-2025-41066 - Disclosure of sensitive information in Horde Groupware

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vulnerability, an HTTP request must be sent to ‘/imp/attachment.php’ including the parameters ‘id’ and ‘u’. If the specifie…

📅 Published: Dec. 2, 2025, 2:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:08 p.m.

6.4

CVSS3.1

CVE-2025-13731 - Nexter Extension <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a…

📅 Published: Dec. 2, 2025, 1:53 p.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

7.5

CVSS3.1

CVE-2025-13295 - Sensitive Data Exposure in ArgusTech's BILGER

Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message Identifier.This issue affects BILGER: before 2.4.9.

📅 Published: Dec. 2, 2025, 1:43 p.m. 🔄 Last Modified: Feb. 12, 2026, 5:30 p.m.

6.9

CVSS4.0

CVE-2025-41086 - Authorization bypass in GAMS from GAMS Development Corp.

Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate …

📅 Published: Dec. 2, 2025, 1:22 p.m. 🔄 Last Modified: Feb. 3, 2026, 5:19 p.m.

6.9

CVSS4.0

CVE-2025-41015 - User Enumeration vulnerability in TCMAN GIM

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetUserQuestionAndAnswer' in '/WS/PDAWebSe…

📅 Published: Dec. 2, 2025, 1:18 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:08 p.m.

6.9

CVSS4.0

CVE-2025-41014 - User Enumeration vulnerability in TCMAN GIM

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebS…

📅 Published: Dec. 2, 2025, 1:18 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:07 p.m.

8.7

CVSS4.0

CVE-2025-41013 - SQL injection vulnerability in TCMAN GIM

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

📅 Published: Dec. 2, 2025, 1:13 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:54 p.m.

8.7

CVSS4.0

CVE-2025-41012 - Unauthorized access vulnerability in TCMAN GIM

Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'.

📅 Published: Dec. 2, 2025, 1:12 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:46 p.m.

5.1

CVSS4.0

CVE-2025-40700 - Reflected Cross-Site Scripting (XSS) in Governalia by IDI Eikon

Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such a…

📅 Published: Dec. 2, 2025, 1:08 p.m. 🔄 Last Modified: Jan. 30, 2026, 7:13 p.m.

7.1

CVSS4.0

CVE-2025-11789 - Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the parameter is too large, it will access memory bey…

📅 Published: Dec. 2, 2025, 1:04 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:18 p.m.
Total resulsts: 349182
Page 2849 of 34,919
« previous page » next page
Filters