9.8

CVSS3.1

CVE-2024-51978 - Authentication bypass via default password generation affecting multiple models from Brother Indust…

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP requ…

πŸ“… Published: June 25, 2025, 7:17 a.m. πŸ”„ Last Modified: March 30, 2026, 6:04 p.m.

5.3

CVSS3.1

CVE-2024-51977 - Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Lt…

An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no a…

πŸ“… Published: June 25, 2025, 7:15 a.m. πŸ”„ Last Modified: March 30, 2026, 3:47 p.m.

5.3

CVSS4.0

CVE-2025-43880 -

Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.

πŸ“… Published: June 25, 2025, 5:31 a.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

7.6

CVSS3.1

CVE-2025-0966 - IBM InfoSphere Information Server SQL injection

IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

πŸ“… Published: June 25, 2025, 2:40 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-36004 - IBM i privilege escalation

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

πŸ“… Published: June 25, 2025, 2:32 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.4

CVSS3.1

CVE-2025-5585 - SiteOrigin Widgets Bundle <= 1.68.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with …

πŸ“… Published: June 25, 2025, 2:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

5.3

CVSS4.0

CVE-2025-6583 - SourceCodester Best Salon Management System view-appointment.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view-appointment.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 4:46 p.m.

7.5

CVSS3.1

CVE-2025-45333 -

berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:06 p.m.

7.1

CVSS3.1

CVE-2024-27685 -

SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 4:16 p.m.

4.6

CVSS3.1

CVE-2025-44206 -

Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.
Total resulsts: 343921
Page 4371 of 34,393
Β« previous page Β» next page
Filters