3.5

CVSS3.1

CVE-2025-55007 - Knowage vulnerable to server-side request forgery

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vโ€ฆ

๐Ÿ“… Published: Sept. 1, 2025, 3:46 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:57 p.m.

6.9

CVSS4.0

CVE-2025-9786 - Campcodes Online Learning Management System teacher_signup.php sql injection

A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /teacher_signup.php. Performing manipulation of the argument firstname results in sql injection. The attack can be initiated remotely. The exploit has been made public and couldโ€ฆ

๐Ÿ“… Published: Sept. 1, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 3:56 p.m.

8.7

CVSS4.0

CVE-2025-9783 - TOTOLINK A702R formParentControl sub_418030 buffer overflow

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly โ€ฆ

๐Ÿ“… Published: Sept. 1, 2025, 2:32 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:52 p.m.

6.1

CVSS3.1

CVE-2025-0656 - IBM Concert Software cross-site scripting

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

๐Ÿ“… Published: Sept. 1, 2025, 2:23 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:05 p.m.

5.4

CVSS3.1

CVE-2025-33082 - IBM Concert Software cross-site scripting

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

๐Ÿ“… Published: Sept. 1, 2025, 2:22 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:05 p.m.

5.4

CVSS3.1

CVE-2025-33083 - IBM Concert Software cross-site scripting

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

๐Ÿ“… Published: Sept. 1, 2025, 2:22 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:05 p.m.

5.9

CVSS3.1

CVE-2025-33084 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

๐Ÿ“… Published: Sept. 1, 2025, 2:20 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:04 p.m.

5.9

CVSS3.1

CVE-2025-33099 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

๐Ÿ“… Published: Sept. 1, 2025, 2:19 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:04 p.m.

5.9

CVSS3.1

CVE-2025-33102 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

๐Ÿ“… Published: Sept. 1, 2025, 2:18 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:04 p.m.

8.7

CVSS4.0

CVE-2025-9782 - TOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflow

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflow. The attack may be initiated remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Sept. 1, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:42 p.m.
Total resulsts: 349182
Page 4063 of 34,919
ยซ previous page ยป next page
Filters