4.3

CVSS3.1

CVE-2025-59450 -

The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.2

CVSS3.1

CVE-2025-59447 -

The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to read a boot log, which includes network access credentials.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-56382 -

A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script or HTML via the 'Customer Name' parameter when creating or editing customer profiles. This malicious input is imprope…

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 6:34 p.m.

5.7

CVSS3.1

CVE-2025-60969 -

Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

9.1

CVSS3.1

CVE-2025-60965 -

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified impacts.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:14 p.m.

8.2

CVSS3.1

CVE-2025-60963 -

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:35 p.m.

8.2

CVSS3.1

CVE-2025-60959 -

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:36 p.m.

8

CVSS3.1

CVE-2025-60956 -

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:36 p.m.

8.2

CVSS3.1

CVE-2025-50538 -

Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 5:03 p.m.

5.4

CVSS3.1

CVE-2025-28129 -

Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

πŸ“… Published: Oct. 6, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 6:40 p.m.
Total resulsts: 349182
Page 3550 of 34,919
Β« previous page Β» next page
Filters