5.4

CVSS3.1

CVE-2025-37728 - Kibana Insufficiently Protected Credentials in the CrowdStrike Connector

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.

πŸ“… Published: Oct. 7, 2025, 1:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-53476 -

A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to the server not processing subsequent Modbus requests. An attacker can open a series of TCP connection…

πŸ“… Published: Oct. 7, 2025, 1:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-13033 - Nodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflict

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email …

πŸ“… Published: Oct. 7, 2025, 1:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2021-22291 - EIBPORT Reflected XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

πŸ“… Published: Oct. 7, 2025, 1:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-11396 - code-projects Simple Food Ordering System product.php sql injection

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: Oct. 7, 2025, 1:02 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:39 p.m.

0.0

CVE-2025-11428 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 7, 2025, 12:41 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 10:19 p.m.

6

CVSS4.0

CVE-2025-40888 - Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0

A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.

πŸ“… Published: Oct. 7, 2025, 12:38 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:37 p.m.

7.2

CVSS4.0

CVE-2025-40889 - Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, …

πŸ“… Published: Oct. 7, 2025, 12:37 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:37 p.m.

6

CVSS4.0

CVE-2025-40887 - Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.

πŸ“… Published: Oct. 7, 2025, 12:37 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:38 p.m.

7.7

CVSS4.0

CVE-2025-40886 - Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering thei…

πŸ“… Published: Oct. 7, 2025, 12:36 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:38 p.m.
Total resulsts: 349182
Page 3523 of 34,919
Β« previous page Β» next page
Filters