5.1

CVSS3.1

CVE-2025-36158 - IBM Concert Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

πŸ“… Published: Nov. 20, 2025, 9:19 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:50 p.m.

6.2

CVSS3.1

CVE-2025-36159 - IBM Concert Improper Log Neutralization

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

πŸ“… Published: Nov. 20, 2025, 9:17 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:49 p.m.

5.3

CVSS3.1

CVE-2025-36160 - IBM Concert Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

πŸ“… Published: Nov. 20, 2025, 9:15 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:46 p.m.

7

CVSS4.0

CVE-2025-62674 - Missing Authentication for RTSP in iCam Cameras

The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

πŸ“… Published: Nov. 20, 2025, 8:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-64770 - Missing Authentication for ONVIF in iCam Cameras

The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

πŸ“… Published: Nov. 20, 2025, 8:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-35029 - Medical Informatics Engineering Enterprise Health stored cross site scripting via Demographic Infor…

Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 202…

πŸ“… Published: Nov. 20, 2025, 7:34 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:51 p.m.

5.4

CVSS3.1

CVE-2025-52668 -

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 8:19 p.m.

8.8

CVSS3.0

CVE-2025-48986 -

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 6:57 p.m.

6.1

CVSS3.1

CVE-2025-48987 -

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

πŸ“… Published: Nov. 20, 2025, 7:11 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 6:56 p.m.

5.4

CVSS3.1

CVE-2025-55123 -

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 8:17 p.m.
Total resulsts: 349182
Page 2947 of 34,919
Β« previous page Β» next page
Filters