8.7

CVSS4.0

CVE-2025-7970 - Rockwell Automation FactoryTalk Activation Manager Lack of Encryption Vulnerability

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.

📅 Published: Sept. 9, 2025, 12:46 p.m. 🔄 Last Modified: Sept. 17, 2025, 3:59 p.m.

8.7

CVSS4.0

CVE-2025-9364 - Rockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DB

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

📅 Published: Sept. 9, 2025, 12:41 p.m. 🔄 Last Modified: Sept. 10, 2025, 2:09 p.m.

8.2

CVSS4.0

CVE-2025-9166 - Rockwell Automation ControlLogix® 5580 V35.013 Denial-Of-Service

A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.

📅 Published: Sept. 9, 2025, 12:36 p.m. 🔄 Last Modified: Oct. 20, 2025, 7:05 p.m.

7

CVSS4.0

CVE-2025-9160 - Rockwell Automation CompactLogix® 5480 Code Execution Vulnerability

A code execution security issue exists in the affected product. An attacker with physical access could abuse the maintenance menu of the controller with a crafted payload. The security issue can result in arbitrary code execution.

📅 Published: Sept. 9, 2025, 12:30 p.m. 🔄 Last Modified: Sept. 9, 2025, 9:31 p.m.

7.1

CVSS4.0

CVE-2025-8007 - Rockwell Automation 1756-ENT2R, EN4TR, EN4TRXT Vulnerability

A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.

📅 Published: Sept. 9, 2025, 12:29 p.m. 🔄 Last Modified: Sept. 17, 2025, 3:47 p.m.

7.1

CVSS4.0

CVE-2025-8008 - Rockwell Automation 1756-ENT2R, EN4TR, EN4TRXT Vulnerability

A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.

📅 Published: Sept. 9, 2025, 12:27 p.m. 🔄 Last Modified: Sept. 17, 2025, 3:42 p.m.

5.3

CVSS4.0

CVE-2025-10095 - SQL injection in SMPP component of SMSEagle firmware

A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certain parameters within the server's database interactions. The vulnerability is isolated to the SMPP server, which operates with its own dedicated datab…

📅 Published: Sept. 9, 2025, 9:59 a.m. 🔄 Last Modified: Sept. 11, 2025, 3:13 p.m.

8.8

CVSS3.1

CVE-2025-48208 - Apache HertzBeat (incubating): Jmx JNDI injection vulnerability

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom commands. A successful attack would result in…

📅 Published: Sept. 9, 2025, 9:31 a.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

8.8

CVSS3.1

CVE-2025-24404 - Apache HertzBeat (incubating): RCE by parse http sitemap xml response

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBea…

📅 Published: Sept. 9, 2025, 9:30 a.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-59019 - Information Disclosure via CSV Download

Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.

📅 Published: Sept. 9, 2025, 9:01 a.m. 🔄 Last Modified: Sept. 26, 2025, 2:09 p.m.
Total resulsts: 349182
Page 3949 of 34,919
« previous page » next page
Filters