6.8

CVSS3.1

CVE-2025-25732 -

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to roo…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 3:15 p.m.

6.8

CVSS3.1

CVE-2025-25737 -

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2024-47192 -

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 4:58 p.m.

9.1

CVSS3.1

CVE-2024-39335 -

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 5 p.m.

5.4

CVSS3.1

CVE-2025-52217 -

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:57 p.m.

6.1

CVSS3.1

CVE-2025-52036 -

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of …

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 5:46 p.m.

6.1

CVSS3.1

CVE-2025-52035 -

A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 5:42 p.m.

5.4

CVSS3.1

CVE-2025-50975 -

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing an authenticated administrator to inject persistent JavaScript. This stored XSS payload is exe…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:55 p.m.

6.5

CVSS3.1

CVE-2025-50974 -

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated remote attacker can inject arbitrary OS commands by embedding shell metacharacters in any of …

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:56 p.m.

6.1

CVSS3.1

CVE-2025-52037 -

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commi…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 1:24 p.m.
Total resulsts: 349182
Page 4140 of 34,919
Β« previous page Β» next page
Filters