8.7

CVSS4.0

CVE-2025-10205 - Predictable Salt and Weak Hashing Algorithm

Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.Β and newer versions

πŸ“… Published: Sept. 17, 2025, 2:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2024-48842 - Hardcoded passwords

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

πŸ“… Published: Sept. 17, 2025, 2:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10595 - SourceCodester Online Student File Management System delete_user.php sql injection

A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has…

πŸ“… Published: Sept. 17, 2025, 2:32 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 3:12 p.m.

7.5

CVSS3.1

CVE-2025-40933 - Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely

Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an MD5 hash of the epoch time and a call to the built-in rand function. The epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is u…

πŸ“… Published: Sept. 17, 2025, 2:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10594 - SourceCodester Online Student File Management System delete_student.php sql injection

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead to sql injection. It is possible to launch the attack remotely…

πŸ“… Published: Sept. 17, 2025, 2:02 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 8:23 p.m.

5.3

CVSS4.0

CVE-2025-10593 - SourceCodester Online Student File Management System update_student.php sql injection

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is n…

πŸ“… Published: Sept. 17, 2025, 1:32 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 8:23 p.m.

5.3

CVSS3.1

CVE-2025-59476 - jenkins: Log message injection vulnerability

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislea…

πŸ“… Published: Sept. 17, 2025, 1:17 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-59475 - jenkins: Missing permission check in authenticated users' profile menu

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., …

πŸ“… Published: Sept. 17, 2025, 1:17 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-59474 - jenkins: Missing permission check allows obtaining agent names

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

πŸ“… Published: Sept. 17, 2025, 1:17 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-10592 - itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be p…

πŸ“… Published: Sept. 17, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:16 p.m.
Total resulsts: 349182
Page 3807 of 34,919
Β« previous page Β» next page
Filters