8.5

CVSS4.0

CVE-2025-8393 - Dreame Technology iOS and Android Mobile Applications Improper Certificate Validation

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credent…

πŸ“… Published: Aug. 8, 2025, 4:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-46414 - EG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication Attempts

The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial number. The API provides clear feedback when the correct PIN…

πŸ“… Published: Aug. 8, 2025, 4:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-47872 - EG4 Electronics EG4 Inverters Observable Discrepancy

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to g…

πŸ“… Published: Aug. 8, 2025, 4:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-53520 - EG4 Electronics EG4 Inverters Download of Code Without Integrity Check

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive fo…

πŸ“… Published: Aug. 8, 2025, 4:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-52586 - EG4 Electronics EG4 Inverters Cleartext Transmission of Sensitive Information

The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data, including read/write oper…

πŸ“… Published: Aug. 8, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4576 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows an …

πŸ“… Published: Aug. 8, 2025, 3:42 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 3:54 p.m.

9.8

CVSS3.1

CVE-2025-8356 - Path Traversal leading to RCE

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

πŸ“… Published: Aug. 8, 2025, 3:40 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

9.3

CVSS4.0

CVE-2025-8731 - TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials

A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: Aug. 8, 2025, 3:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-8355 - XXE leading to SSRF

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

πŸ“… Published: Aug. 8, 2025, 3:31 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 4:19 p.m.

6.5

CVSS3.1

CVE-2025-36023 - IBM Cloud Pak for Business Automation security bypass

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

πŸ“… Published: Aug. 8, 2025, 2:51 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 6:19 p.m.
Total resulsts: 349182
Page 4368 of 34,919
Β« previous page Β» next page
Filters