9.3

CVSS4.0

CVE-2025-59736 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_DJO.ASP'.

📅 Published: Oct. 2, 2025, 2:01 p.m. 🔄 Last Modified: Oct. 2, 2025, 8:05 p.m.

9.3

CVSS4.0

CVE-2025-59735 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM.ASP'.

📅 Published: Oct. 2, 2025, 1:59 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:58 p.m.

6.9

CVSS4.0

CVE-2025-53881 - SUSE-specific logrotate configuration allows escalation from mail user/group to root

A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.

📅 Published: Oct. 2, 2025, 1:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-22862 -

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their …

📅 Published: Oct. 2, 2025, 12:48 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

6.3

CVSS3.1

CVE-2025-0642 - Hard-coded Credentials in PosCube's Assist

Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass.This issue affects Assist: through 10.02.2025.

📅 Published: Oct. 2, 2025, 12:37 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11240 - Open redirect vulnerability in KNIME Business Hub

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. This might open the possi…

📅 Published: Oct. 2, 2025, 12:30 p.m. 🔄 Last Modified: Oct. 8, 2025, 5:17 p.m.

2.3

CVSS4.0

CVE-2025-11239 - Job details are visible to all team members on KNIME Business Hub

Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadata of jobs is shown to team members. Only the creator of a job can see all information including in- and output data (if…

📅 Published: Oct. 2, 2025, 12:23 p.m. 🔄 Last Modified: Oct. 8, 2025, 5:17 p.m.

5.1

CVSS4.0

CVE-2025-41010 - Cross-origin resource sharing (CORS) in Hiberus Sintra

Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identifies the domain making the initial request and defines the protoc…

📅 Published: Oct. 2, 2025, 12:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2024-58260 - Rancher update on users can deny the service to the admin

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.

📅 Published: Oct. 2, 2025, 12:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-58267 - Rancher CLI SAML authentication is vulnerable to phishing attacks

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

📅 Published: Oct. 2, 2025, 12:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3594 of 34,919
« previous page » next page
Filters