6.9

CVSS4.0

CVE-2025-11852 - Apeman ID71 ONVIF Service device_service missing authentication

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the component ONVIF Service. Performing manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been m…

📅 Published: Oct. 16, 2025, 7:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-11493 - Self-Update Verification Mechanism Process in ConnectWise Automate

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by im…

📅 Published: Oct. 16, 2025, 7 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:57 p.m.

9.6

CVSS3.1

CVE-2025-11492 - HTTP Configuration and Encryption in Transit

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some co…

📅 Published: Oct. 16, 2025, 6:59 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:57 p.m.

8.8

CVSS4.0

CVE-2025-62428 - Drawing-Captcha APP Host Header Injection in `/register` and `/confirm-email` Endpoints

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links…

📅 Published: Oct. 16, 2025, 6:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-34253 - D-Link Nuclias Connect <= v1.3.1.4 Stored Cross-Site Scripting (XSS)

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be…

📅 Published: Oct. 16, 2025, 6:53 p.m. 🔄 Last Modified: Nov. 28, 2025, 7:26 p.m.

6.9

CVSS4.0

CVE-2025-34255 - D-Link Nuclias Connect <= v1.3.1.4 Forgot Password Account Enumeration

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses di…

📅 Published: Oct. 16, 2025, 6:52 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-34254 - D-Link Nuclias Connect <= v1.3.1.4 Login Account Enumeration

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `er…

📅 Published: Oct. 16, 2025, 6:52 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

8.7

CVSS4.0

CVE-2025-62427 - Server-Side Request Forgery (SSRF) in Angular SSR

The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the URL resolution mechanism of Angular's Server-Side Rendering package (@angular/ssr) before 19.2.18, 20.3.6, and 21.0.0-next.8. The function createReques…

📅 Published: Oct. 16, 2025, 6:50 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-62425 - Matrix Authentication Service account password can be changed using an authenticated session withou…

MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive opera…

📅 Published: Oct. 16, 2025, 6:44 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-62423 - ClipBucket V5 Blind SQL injection in the Admin Panel

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area.

📅 Published: Oct. 16, 2025, 6:40 p.m. 🔄 Last Modified: Nov. 10, 2025, 7:58 p.m.
Total resulsts: 349182
Page 3386 of 34,919
« previous page » next page
Filters