8.7

CVSS4.0

CVE-2025-34518 - Ilevia EVE X1 Server 4.7.18.0.eden Relative Path Traversal

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

📅 Published: Oct. 16, 2025, 5:55 p.m. 🔄 Last Modified: March 23, 2026, 3:44 p.m.

9.3

CVSS4.0

CVE-2025-34515 - Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to t…

📅 Published: Oct. 16, 2025, 5:54 p.m. 🔄 Last Modified: March 23, 2026, 3:44 p.m.

3.8

CVSS3.1

CVE-2025-62412 - LibreNMS alert-rules Cross-Site Scripting Vulnerability

LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.

📅 Published: Oct. 16, 2025, 5:54 p.m. 🔄 Last Modified: Oct. 23, 2025, 12:31 p.m.

9.3

CVSS4.0

CVE-2025-34513 - Ilevia EVE X1 Server 4.7.18.0.eden Unauthenticated Command Injection

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to…

📅 Published: Oct. 16, 2025, 5:53 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

9.3

CVSS4.0

CVE-2025-34516 - Ilevia EVE X1 Server 4.7.18.0.eden Use of Default Credentials

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

📅 Published: Oct. 16, 2025, 5:52 p.m. 🔄 Last Modified: March 23, 2026, 3:44 p.m.

5.5

CVSS3.1

CVE-2025-62411 - Stored XSS in Alert Transport name field in LibreNMS

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport name field is stored…

📅 Published: Oct. 16, 2025, 5:50 p.m. 🔄 Last Modified: Oct. 23, 2025, 12:31 p.m.

6.6

CVSS4.0

CVE-2025-62409 - Envoy allows large requests and responses to cause TCP connection pool crash

Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP connection pool crashes due to flow control management in Envoy. It will happen when the connection is closing but upstream data is sti…

📅 Published: Oct. 16, 2025, 5:47 p.m. 🔄 Last Modified: Oct. 29, 2025, 7:55 p.m.

6.1

CVSS3.1

CVE-2025-62407 - Frappe has an Open Redirect on Login Page

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83.0.

📅 Published: Oct. 16, 2025, 5:39 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:16 p.m.

3.8

CVSS3.1

CVE-2025-61924 - PrestaShop Checkout Target PayPal merchant account hijacking from backoffice

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known…

📅 Published: Oct. 16, 2025, 5:33 p.m. 🔄 Last Modified: Dec. 29, 2025, 8:06 p.m.

4.1

CVSS3.1

CVE-2025-61923 - PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No …

📅 Published: Oct. 16, 2025, 5:31 p.m. 🔄 Last Modified: Dec. 29, 2025, 8:06 p.m.
Total resulsts: 349182
Page 3388 of 34,919
« previous page » next page
Filters