9.8

CVSS3.1

CVE-2025-56267 -

A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 8:42 p.m.

9.8

CVSS3.1

CVE-2025-52161 -

Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 9 p.m.

9.8

CVSS3.1

CVE-2025-22956 -

OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password …

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2022-50238 -

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possib…

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-57141 -

rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 8:57 p.m.

8.4

CVSS3.1

CVE-2025-55849 -

WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 6:21 p.m.

3.7

CVSS3.1

CVE-2024-48341 -

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 3:42 p.m.

7.3

CVSS3.1

CVE-2025-56630 -

FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 9:32 p.m.

8.8

CVSS3.1

CVE-2025-56265 -

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 8:47 p.m.

7.4

CVSS3.1

CVE-2025-59033 -

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileA…

πŸ“… Published: Sept. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3967 of 34,919
Β« previous page Β» next page
Filters