5.5

CVSS3.1

CVE-2025-9435 - Path Traversal

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

📅 Published: Jan. 13, 2026, 1:14 p.m. 🔄 Last Modified: Jan. 13, 2026, 1:14 p.m.

8.8

CVSS3.1

CVE-2025-13774 - SQL injection leading to privilege escalation in Progress Flowmon ADS

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.

📅 Published: Jan. 13, 2026, 12:59 p.m. 🔄 Last Modified: Jan. 13, 2026, 12:59 p.m.

5.2

CVSS4.0

CVE-2026-0859 - TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool

TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.…

📅 Published: Jan. 13, 2026, 11:54 a.m. 🔄 Last Modified: Jan. 13, 2026, 11:54 a.m.

7.1

CVSS4.0

CVE-2025-59022 - TYPO3 CMS Allows Broken Access Control in Recycler Module

Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavaila…

📅 Published: Jan. 13, 2026, 11:53 a.m. 🔄 Last Modified: Jan. 13, 2026, 11:53 a.m.

5.3

CVSS4.0

CVE-2025-59021 - TYPO3 CMS Allows Broken Access Control in Redirects Module

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs …

📅 Published: Jan. 13, 2026, 11:53 a.m. 🔄 Last Modified: Jan. 13, 2026, 11:53 a.m.

5.3

CVSS4.0

CVE-2025-59020 - TYPO3 CMS Allows Broken Access Control in Edit Document Controller

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set…

📅 Published: Jan. 13, 2026, 11:53 a.m. 🔄 Last Modified: Jan. 13, 2026, 11:53 a.m.

5.4

CVSS3.1

CVE-2025-14001 - WP Duplicate Page <= 1.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Dup…

The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkHandle' and 'duplicateBulkHandleHPOS' functions in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Con…

📅 Published: Jan. 13, 2026, 11:21 a.m. 🔄 Last Modified: Jan. 13, 2026, 11:21 a.m.

8.7

CVSS4.0

CVE-2025-40944 -

A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS …

📅 Published: Jan. 13, 2026, 9:44 a.m. 🔄 Last Modified: Jan. 13, 2026, 9:44 a.m.

7.3

CVSS4.0

CVE-2025-40942 -

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges.

📅 Published: Jan. 13, 2026, 9:44 a.m. 🔄 Last Modified: Jan. 13, 2026, 9:44 a.m.

10

CVSS4.0

CVE-2025-40805 -

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimat…

📅 Published: Jan. 13, 2026, 9:44 a.m. 🔄 Last Modified: Jan. 13, 2026, 9:44 a.m.
Total resulsts: 327160
Page 3 of 32,716
« previous page » next page
Filters