5.3

CVSS3.1

CVE-2025-43889 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation of a Pathname to a Restricted Directory โ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:37 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:11 p.m.

5.3

CVSS4.0

CVE-2025-11404 - SourceCodester Hotel and Lodge Management System save_tax.php sql injection

A vulnerability was determined in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown part of the file /pages/save_tax.php. Executing manipulation of the argument percentage can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publiโ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 4:23 p.m.

6

CVSS3.1

CVE-2025-43934 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation ofโ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:30 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:08 p.m.

6.4

CVSS3.1

CVE-2025-43908 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralizatioโ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:22 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

2.3

CVSS4.0

CVE-2025-3449 - Weak Session Token used in Automation Runtime SDM

A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.

๐Ÿ“… Published: Oct. 7, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-3448 - XSS on SDM

Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked userโ€™s browser session

๐Ÿ“… Published: Oct. 7, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-43907 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a Path Traversal: '.../..โ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:14 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:10 p.m.

4.3

CVSS3.1

CVE-2025-8291 - ZIP64 End of Central Directory (EOCD) Locator record offset not checked

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create Zโ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:10 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:15 p.m.

6.7

CVSS3.1

CVE-2025-43911 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralizatioโ€ฆ

๐Ÿ“… Published: Oct. 7, 2025, 6:08 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.3

CVSS4.0

CVE-2025-3450 - Automation Runtime SDM requests may impact system

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

๐Ÿ“… Published: Oct. 7, 2025, 6:03 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3519 of 34,919
ยซ previous page ยป next page
Filters