8.5

CVSS4.0

CVE-2025-27262 - Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command V…

Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

📅 Published: Sept. 25, 2025, 2:43 p.m. 🔄 Last Modified: Oct. 2, 2025, 6:01 p.m.

3.3

CVSS3.1

CVE-2025-36857 - Rapid7 Appspider Broken Access Control Vulnerability

Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom con…

📅 Published: Sept. 25, 2025, 2:41 p.m. 🔄 Last Modified: Dec. 11, 2025, 6:20 p.m.

7.5

CVSS3.1

CVE-2025-59830 - Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated paramet…

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters t…

📅 Published: Sept. 25, 2025, 2:37 p.m. 🔄 Last Modified: Oct. 10, 2025, 4:43 p.m.

9.8

CVSS3.1

CVE-2025-10542 - Insecure Default Admin Credentials Enable Full Administrative Access in iMonitor EAM

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data.…

📅 Published: Sept. 25, 2025, 2:35 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10950 - geyang ml-logger Ping server.py log_handler deserialization

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This manipulation of the argument data causes deserialization. It is possible to initiate the attack…

📅 Published: Sept. 25, 2025, 2:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-10949 - Changsha Developer Technology iView Editor Markdown cross site scripting

A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The…

📅 Published: Sept. 25, 2025, 2:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-10541 - Local Privilege Escalation via Insecure Update Mechanism in iMonitor EAM

iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can create and write to this …

📅 Published: Sept. 25, 2025, 2:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.0

CVE-2025-59823 - Gardener providers vulnerable to code injection when Terraformer is used for infrastructure provisi…

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.0, OpenStack providers prior to version 1.49.0, and GCP prov…

📅 Published: Sept. 25, 2025, 2:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-10540 - Unencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAM

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credent…

📅 Published: Sept. 25, 2025, 2:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-10948 - MikroTik RouterOS libjson.so print parse_json_element buffer overflow

A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the pub…

📅 Published: Sept. 25, 2025, 2:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3684 of 34,919
« previous page » next page
Filters