6.9

CVSS4.0

CVE-2025-11488 - D-Link DIR-852 HNAP1 command injection

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. This vulnerability …

πŸ“… Published: Oct. 8, 2025, 6:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11487 - SourceCodester Farm Management System uploadProduct.php sql injection

A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing manipulation of the argument Type results in sql injection. The attack may be initiated remotely. The exploit has been re…

πŸ“… Published: Oct. 8, 2025, 5:32 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4 p.m.

5.6

CVSS3.1

CVE-2025-42701 - CrowdStrike Falcon Sensor for Windows Race Condition

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (L…

πŸ“… Published: Oct. 8, 2025, 5:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-42706 - CrowdStrike Falcon Sensor for Windows Logic Error

A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV)…

πŸ“… Published: Oct. 8, 2025, 5:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-9868 - Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

πŸ“… Published: Oct. 8, 2025, 5:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11486 - SourceCodester Farm Management System buyNow.php sql injection

A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and …

πŸ“… Published: Oct. 8, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

4.8

CVSS4.0

CVE-2025-11485 - SourceCodester Student Grades Management System Manage Users admin.php add_user cross site scripting

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user of the file /admin.php of the component Manage Users Page. This manipulation of the argument first_name/last_name causes cross site scripting. The attack can be initiated remotel…

πŸ“… Published: Oct. 8, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:02 p.m.

5.7

CVSS4.0

CVE-2025-9970 - Application credential stored in clear text in memory

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

πŸ“… Published: Oct. 8, 2025, 4:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11481 - varunsardana004 Blood-Bank-And-Donation-Management-System donate_blood.php sql injection

A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12cba1919df2. The impacted element is an unknown function of the file /donate_blood.php. Executing manipulation of the argument fullname can lead to sql injection. The attack may be …

πŸ“… Published: Oct. 8, 2025, 4:32 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:05 p.m.

1

CVSS4.0

CVE-2025-5009 - Information Disclosure in Gemini iOS App

In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained the entire conversation history and not just the snippet.

πŸ“… Published: Oct. 8, 2025, 3:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3507 of 34,919
Β« previous page Β» next page
Filters