6.5

CVSS3.1

CVE-2025-60538 -

A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:16 p.m.

5.4

CVSS3.1

CVE-2025-67282 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 4:16 p.m.

5.3

CVSS3.1

CVE-2025-67279 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-51626 -

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:15 p.m.

8.2

CVSS3.1

CVE-2025-67070 -

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and gain full access to th…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:16 p.m.

0.0

CVE-2025-67004 -

An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:24 p.m.

6.5

CVSS3.1

CVE-2025-66715 -

A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:16 p.m.

0.0

CVE-2025-66744 -

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:24 p.m.

6.5

CVSS3.1

CVE-2025-67811 -

Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote attackers to inject arbitrary SQL commands, resulting in unauthorized database access and potential compromise of sensitive data. Fixed in v.1.47.4 an…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-67810 -

In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 10:16 p.m.
Total resulsts: 327160
Page 36 of 32,716
Β« previous page Β» next page
Filters