7.1

CVSS4.0

CVE-2025-41035 - Path Traversal vulnerability in appRain CMF

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the …

πŸ“… Published: Sept. 4, 2025, 11:07 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:44 p.m.

8.7

CVSS4.0

CVE-2025-41034 - SQL injection vulnerability in appRain CMF

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through theΒ 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-static-pages/create/.

πŸ“… Published: Sept. 4, 2025, 11:06 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:45 p.m.

8.7

CVSS4.0

CVE-2025-41033 - SQL injection vulnerability in appRain CMF

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through theΒ 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create.

πŸ“… Published: Sept. 4, 2025, 11:06 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:45 p.m.

8.7

CVSS4.0

CVE-2025-41032 - SQL injection vulnerability in appRain CMF

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through theΒ 'data%5BAdmin%5D%5Busername%5D' parameter in /apprain/admin/manage/add/.

πŸ“… Published: Sept. 4, 2025, 11:06 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:45 p.m.

7.7

CVSS3.1

CVE-2024-34598 -

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

πŸ“… Published: Sept. 4, 2025, 10:55 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 7:16 p.m.

4.3

CVSS3.1

CVE-2022-39888 -

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

πŸ“… Published: Sept. 4, 2025, 10:52 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-6085 - Make Connector <= 1.5.10 - Authenticated (Administrator+) Arbitrary File Upload

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and including, 1.5.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to up…

πŸ“… Published: Sept. 4, 2025, 9:22 a.m. πŸ”„ Last Modified: April 20, 2026, 10 p.m.

5.3

CVSS3.1

CVE-2025-9616 - PopAd <= 1.0.4 - Cross-Site Request Forgery to Settings Update

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the PopAd_reset_cookie_time function. This makes it possible for unauthenticated attackers to reset cookie time settings vi…

πŸ“… Published: Sept. 4, 2025, 9:22 a.m. πŸ”„ Last Modified: April 21, 2026, 3:30 a.m.

8.6

CVSS3.1

CVE-2025-2411 - OTP Bypass in Akinsoft's TaskPano

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass.This issue affects TaskPano: from s1.06.04 before v1.06.06.

πŸ“… Published: Sept. 4, 2025, 8:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-13073 - XSS in Akinsoft's TaskPano

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

πŸ“… Published: Sept. 4, 2025, 8:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4017 of 34,919
Β« previous page Β» next page
Filters