0.0

CVE-2025-57845 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-34158. Reason: This candidate is a reservation duplicate of CVE-2025-34158. Notes: All CVE users should reference CVE-2025-34158 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:05 a.m.

7.3

CVSS3.1

CVE-2025-55524 -

Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 2:22 p.m.

5.3

CVSS3.1

CVE-2025-55367 -

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:11 p.m.

8.1

CVSS3.1

CVE-2024-50641 -

An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-55366 -

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:11 p.m.

3.5

CVSS3.1

CVE-2025-55523 -

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 2:28 p.m.

7.5

CVSS3.1

CVE-2025-55564 -

Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Sept. 3, 2025, 2:53 p.m.

8.8

CVSS3.1

CVE-2025-55420 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:12 p.m.

9.8

CVSS3.1

CVE-2025-52352 -

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing unauthenticated users to regis…

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-47184 -

An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4189 of 34,919
Β« previous page Β» next page
Filters