9.1

CVSS3.1

CVE-2025-55443 -

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these logs to: 1. Authenticate to the MDM web platfor…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:54 p.m.

6.5

CVSS3.1

CVE-2025-52219 -

SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML Injection.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:56 p.m.

7.8

CVSS3.1

CVE-2025-38676 - iommu/amd: Avoid stack buffer overflow from kernel cmdline

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environments, avoid writing 1 byte past the end of "acpiid" if the "str" argument is maximum length.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:30 p.m.

8.4

CVSS3.1

CVE-2025-50753 -

Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" is supposed to be used from restricted shell to show files and directories. By providing " /bin/sh" (quotes included) to the argument of this command will drop a…

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-25734 -

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 3:15 p.m.

6.1

CVSS3.1

CVE-2025-52184 -

Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:55 p.m.

6.1

CVSS3.1

CVE-2025-50976 -

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:55 p.m.

7.5

CVSS3.1

CVE-2025-50971 -

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 4, 2025, 6:35 p.m.

8.8

CVSS3.1

CVE-2024-47853 -

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 22, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-45753 -

In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.

πŸ“… Published: Aug. 26, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 5:04 p.m.
Total resulsts: 349182
Page 4141 of 34,919
Β« previous page Β» next page
Filters