6.5

CVSS3.1

CVE-2025-55824 -

ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtain sensitive data on the server.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 6:06 p.m.

7.5

CVSS3.1

CVE-2025-54599 -

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root …

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:48 p.m.

5.3

CVSS3.1

CVE-2025-32098 -

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 7:33 p.m.

6.5

CVSS3.1

CVE-2025-55472 -

SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerability arises due to unsafe handling of user-supplied input in the columns[0][data] parameter, which is directly used in SQL queries without proper validation or parameterization.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 9:19 p.m.

6.1

CVSS3.1

CVE-2025-55474 -

Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScript when viewed.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 6:01 p.m.

7.5

CVSS3.1

CVE-2025-57613 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor function allows an attacker to cause a denial of service. The vulnerability is triggered when the avio_alloc_context() call fails and returns NULL, which is then st…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:33 p.m.

6.1

CVSS3.1

CVE-2024-51423 -

Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:55 p.m.

7.5

CVSS3.1

CVE-2025-57615 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, …

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:31 p.m.

9.8

CVSS3.1

CVE-2025-57140 -

rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 4, 2025, 5:46 p.m.

5.1

CVSS4.0

CVE-2025-9802 - RemoteClinic profile.php sql injection

A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely.

πŸ“… Published: Sept. 1, 2025, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4060 of 34,919
Β« previous page Β» next page
Filters