5.3

CVSS4.0

CVE-2025-10772 - huggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authentication

A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication. The attack can onl…

πŸ“… Published: Sept. 21, 2025, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10771 - jeecgboot JimuReport DB2 JDBC testConnection deserialization

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack ca…

πŸ“… Published: Sept. 21, 2025, 11:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:42 p.m.

5.3

CVSS4.0

CVE-2025-10770 - jeecgboot JimuReport MySQL JDBC testConnection deserialization

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has …

πŸ“… Published: Sept. 21, 2025, 10:32 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:52 p.m.

2

CVSS4.0

CVE-2025-10767 - CosmodiumCS OnlyRAT Configuration File main.py remote_download os command injection

A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_upload/remote_download of the file main.py of the component Configuration File Handler. The manipulation of the argument configuration["PASSWORD"] results in os command injection. The …

πŸ“… Published: Sept. 21, 2025, 10:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-53692 - Sitecore Experience Platform Cross-Site Scripting Vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Exp…

πŸ“… Published: Sept. 21, 2025, 7:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10769 - h2oai h2o-3 H2 JDBC Driver ImportSQLTable deserialization

A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be launched remotely. The exploit has been disclose…

πŸ“… Published: Sept. 21, 2025, 9:33 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:58 p.m.

5.3

CVSS4.0

CVE-2025-10768 - h2oai h2o-3 IBMDB2 JDBC Driver ImportSQLTable deserialization

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The exploit has been pub…

πŸ“… Published: Sept. 21, 2025, 9:33 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 8:04 p.m.

9.8

CVSS3.0

CVE-2025-6544 - Deserialization Vulnerability in h2oai/h2o-3

A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be exploited by bypassing regular expression checks and …

πŸ“… Published: Sept. 21, 2025, 9 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 8:05 p.m.

5.3

CVSS4.0

CVE-2025-10766 - SeriaWei ZKEACMS EventViewerController.cs Download path traversal

A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument ID can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the…

πŸ“… Published: Sept. 21, 2025, 7:02 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:59 p.m.

5.1

CVSS4.0

CVE-2025-10765 - SeriaWei ZKEACMS SEOSuggestions ZKEACMS.SEOSuggestions.dll server-side request forgery

A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEOSuggestions\ZKEACMS.SEOSuggestions.dll of the component SEOSuggestions. Performing manipulation results in server-side …

πŸ“… Published: Sept. 21, 2025, 6:32 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:44 p.m.
Total resulsts: 349182
Page 3760 of 34,919
Β« previous page Β» next page
Filters