5.1

CVSS4.0

CVE-2025-6694 - LabRedesCefetRJ WeGIA Adicionar Unidade adicionar_unidade.php cross site scripting

A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects unknown code of the file /html/matPat/adicionar_unidade.php of the component Adicionar Unidade. The manipulation of the argument Insira a nova unidade leads to cross site scriptin…

📅 Published: June 26, 2025, 1:31 p.m. 🔄 Last Modified: July 1, 2025, 7:03 p.m.

8.5

CVSS4.0

CVE-2025-6693 - RT-Thread device.c sys_device_write memory corruption

A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/device.c. The manipulation leads to memory corrup…

📅 Published: June 26, 2025, 1 p.m. 🔄 Last Modified: July 11, 2025, 2:27 p.m.

8.1

CVSS3.1

CVE-2025-5966 - Stored XSS

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

📅 Published: June 26, 2025, 12:22 p.m. 🔄 Last Modified: Sept. 29, 2025, 2:49 p.m.

8.1

CVSS3.1

CVE-2025-5366 - Stored XSS

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.

📅 Published: June 26, 2025, 12:21 p.m. 🔄 Last Modified: Sept. 29, 2025, 2:49 p.m.

8.7

CVSS4.0

CVE-2025-6562 - Hunt Electronic Hybrid DVR - OS Command Injection

Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.

📅 Published: June 26, 2025, 12:12 p.m. 🔄 Last Modified: June 26, 2025, 6:57 p.m.

9.8

CVSS3.1

CVE-2025-6561 - Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information

Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.

📅 Published: June 26, 2025, 11:45 a.m. 🔄 Last Modified: June 26, 2025, 6:57 p.m.

0

CVSS4.0

CVE-2025-3773 -

A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.

📅 Published: June 26, 2025, 11:11 a.m. 🔄 Last Modified: Feb. 11, 2026, 9:39 p.m.

0

CVSS4.0

CVE-2025-3722 -

A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files a…

📅 Published: June 26, 2025, 11:08 a.m. 🔄 Last Modified: Feb. 11, 2026, 9:40 p.m.

7.2

CVSS4.0

CVE-2025-3771 -

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a malicious entry to the registry under the Trelli…

📅 Published: June 26, 2025, 11:05 a.m. 🔄 Last Modified: Feb. 11, 2026, 9:40 p.m.

2.3

CVSS4.0

CVE-2025-6703 - transport/fc.rs: panic attempting to send MAX_DATA with value larger max varint

Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.

📅 Published: June 26, 2025, 9:30 a.m. 🔄 Last Modified: Dec. 3, 2025, 8:41 p.m.
Total resulsts: 343825
Page 4345 of 34,383
« previous page » next page
Filters