8.5

CVSS3.1

CVE-2025-59146 - New API has Authenticated Server-Side Request Forgery (SSRF) issue

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature within the application allows authenticated users to submit a URL for the server …

📅 Published: Oct. 9, 2025, 6:58 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:07 p.m.

7.1

CVSS3.1

CVE-2025-55200 - BigBlueButton vulnerable to Stored XSS via name of user at Shared Notes

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "Shared Notes" page, when a user with a malicious u…

📅 Published: Oct. 9, 2025, 6:51 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:51 p.m.

7

CVSS4.0

CVE-2025-4615 - PAN-OS: Improper Neutralization of Input in the Management Web Interface

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI a…

📅 Published: Oct. 9, 2025, 6:28 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:28 p.m.

4.8

CVSS4.0

CVE-2025-4614 - PAN-OS: Session Token Disclosure Vulnerability

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   The security risk posed by this issue…

📅 Published: Oct. 9, 2025, 6:13 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:13 p.m.

5.3

CVSS4.0

CVE-2025-11551 - code-projects Student Result Manager Database.java sql injection

A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly di…

📅 Published: Oct. 9, 2025, 6:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:02 p.m.

7.1

CVSS4.0

CVE-2025-11550 - Tenda W12 HTTP Request modules wifiScheduledSet null pointer dereference

A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument wifiScheduledSet results in null pointer dereference. The attack may be performed from remo…

📅 Published: Oct. 9, 2025, 6:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:02 p.m.

8.7

CVSS4.0

CVE-2025-11573 - Denial of Service issue in Amazon.IonDotnet

An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not rec…

📅 Published: Oct. 9, 2025, 5:48 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:48 p.m.

8.7

CVSS4.0

CVE-2025-11549 - Tenda W12 HTTP Request modules wifiMacFilterSet stack-based overflow

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out rem…

📅 Published: Oct. 9, 2025, 5:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:02 p.m.

9.3

CVSS4.0

CVE-2017-20203 - NetSarang v5.0 Malicious Backdoor Supply Chain Compromise

NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT reco…

📅 Published: Oct. 9, 2025, 5:01 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:01 p.m.

0.0

CVE-2025-11371 - Gladinet CentreStack and TrioFox Local File Inclusion Flaw

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and…

📅 Published: Oct. 9, 2025, 4:50 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.
Total resulsts: 313830
Page 34 of 31,383
« previous page » next page
Filters