8.7

CVSS4.0

CVE-2025-34185 - Ilevia EVE X1 Server 4.7.18.0.eden Unauthenticated File Disclosure

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.

πŸ“… Published: Sept. 16, 2025, 7:44 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

9.3

CVSS4.0

CVE-2025-34184 - Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or den…

πŸ“… Published: Sept. 16, 2025, 7:40 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

9.3

CVSS4.0

CVE-2025-34183 - Ilevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log Disclosure

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential re…

πŸ“… Published: Sept. 16, 2025, 7:39 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-10562 - Campcodes Grocery Sales and Inventory System ajax.php sql injection

A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be …

πŸ“… Published: Sept. 16, 2025, 7:02 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 4:50 p.m.

4

CVSS3.1

CVE-2025-49728 - Microsoft PC Manager Security Feature Bypass Vulnerability

Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

πŸ“… Published: Sept. 16, 2025, 6:13 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 4 p.m.

4.7

CVSS3.1

CVE-2025-47967 - Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: Sept. 16, 2025, 6:13 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 4 p.m.

0.0

CVE-2025-10572 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-9199. Reason: This candidate is a reservation duplicate of CVE-2025-9199. Notes: All CVE users should reference CVE-2025-9199 instead of this candidate. All references and descriptions in this candidate have been removed to prevent…

πŸ“… Published: Sept. 16, 2025, 5:48 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 5:59 p.m.

5.5

CVSS3.1

CVE-2025-54237 - Substance3D - Stager | Out-of-bounds Read (CWE-125)

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a …

πŸ“… Published: Sept. 16, 2025, 5:27 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 1:38 p.m.

7.8

CVSS3.1

CVE-2025-54262 - Substance3D - Stager | Out-of-bounds Read (CWE-125)

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current us…

πŸ“… Published: Sept. 16, 2025, 5:23 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

6.9

CVSS4.0

CVE-2025-59336 - Relative Path Traversal in Luanox

Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec verification system. This cause…

πŸ“… Published: Sept. 16, 2025, 4:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3821 of 34,919
Β« previous page Β» next page
Filters