6.5

CVSS3.1

CVE-2025-57433 -

The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpoint (/cwi/ajax_request/get_data.php), an authenticated attacker (even with a low-privileged account like guest) can retrieve the hashed passwords for …

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 7:56 p.m.

9.8

CVSS3.1

CVE-2025-57432 -

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanism…

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 7:56 p.m.

8.8

CVSS3.1

CVE-2025-57431 -

The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repa…

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 7:53 p.m.

7.5

CVSS3.1

CVE-2025-57430 -

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 7:57 p.m.

5.4

CVSS3.1

CVE-2025-57204 -

Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulnerability within the Products module available to authenticated users. The vulnerability resides in the product name parameter submitted to the product-creation endpoint via a stan…

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 5:45 p.m.

5.4

CVSS3.1

CVE-2025-56075 -

A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 7:14 p.m.

6.5

CVSS3.1

CVE-2025-55886 -

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-55885 -

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 7:52 p.m.

4.3

CVSS3.1

CVE-2025-59800 - Artifex Ghostscript: From CVEorg collector

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 7:27 p.m.

8.8

CVSS3.1

CVE-2025-43953 -

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP screen.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3758 of 34,919
Β« previous page Β» next page
Filters