5.3

CVSS4.0

CVE-2025-8126 - deerwms deer-wms-2 export sql injection

A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: July 25, 2025, 1:32 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 10:50 a.m.

5.3

CVSS4.0

CVE-2025-8125 - deerwms deer-wms-2 allocatedList sql injection

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remot…

πŸ“… Published: July 25, 2025, 1:02 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:56 a.m.

2

CVSS3.1

CVE-2025-0253 - HCL IEM is affected by a cookie attribute not set vulnerability

HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.

πŸ“… Published: July 25, 2025, 12:16 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:49 p.m.

2.6

CVSS3.1

CVE-2025-0252 - HCL IEM is affected by a password in cleartext vulnerability

HCL IEM is affected by a password in cleartext vulnerability.Β  Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.

πŸ“… Published: July 25, 2025, 12:08 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:55 p.m.

2.6

CVSS3.1

CVE-2025-0251 - HCL IEM is affected by a concurrent login vulnerability

HCL IEM is affected by a concurrent login vulnerability.Β  The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.

πŸ“… Published: July 25, 2025, 12:06 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:55 p.m.

9.8

CVSS3.1

CVE-2025-29631 -

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an a…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-48730 -

The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attempts performed by the default admin user, allowing a remote attacker to escalate privileges.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2023-53155 -

goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38457 - net/sched: Abort __tc_modify_qdisc if parent class does not exist

In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class does not exist Lion's patch [1] revealed an ancient bug in the qdisc API. Whenever a user creates/modifies a qdisc specifying as a parent another qdisc, the qdisc API will, durin…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:49 p.m.

4.3

CVSS3.1

CVE-2025-54596 -

Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accounts.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346576
Page 4252 of 34,658
Β« previous page Β» next page
Filters