7.2

CVSS4.0

CVE-2025-52471 - ESP-NOW Integer Underflow Vulnerability Advisory

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.6 of the ESP-IDF framework. This issue stems from insufficie…

πŸ“… Published: June 24, 2025, 7:53 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4:05 p.m.

7.5

CVSS3.1

CVE-2025-52888 - Allure 2's xunit-xml-plugin Vulnerable to Improper XXE Restriction

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) and…

πŸ“… Published: June 24, 2025, 7:45 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

9.3

CVSS4.0

CVE-2025-49853 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID i…

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

πŸ“… Published: June 24, 2025, 7:23 p.m. πŸ”„ Last Modified: July 2, 2025, 4:32 p.m.

8.7

CVSS4.0

CVE-2025-49852 - Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers.

πŸ“… Published: June 24, 2025, 7:19 p.m. πŸ”„ Last Modified: July 2, 2025, 4:33 p.m.

8.7

CVSS4.0

CVE-2025-49851 - Improper Authentication in ControlID iDSecure On-premises

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.

πŸ“… Published: June 24, 2025, 7:17 p.m. πŸ”„ Last Modified: July 2, 2025, 4:33 p.m.

6

CVSS4.0

CVE-2025-5087 - Cleartext Transmission of Sensitive Information in Kaleris Navis N4

Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traffic between Ultra Light Clients and N4 servers can extract sensitive information, including plaintext credentials.

πŸ“… Published: June 24, 2025, 6:30 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

9.3

CVSS4.0

CVE-2025-2566 - Deserialization of Untrusted Data in Kaleris Navis N4

Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.

πŸ“… Published: June 24, 2025, 6:27 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

5.3

CVSS3.1

CVE-2025-49147 - Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously authenticated endpoint it's possible to retrieve information about the configured password requirements. The information …

πŸ“… Published: June 24, 2025, 5:37 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 1:53 p.m.

5

CVSS3.1

CVE-2025-23260 -

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.

πŸ“… Published: June 24, 2025, 5:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:50 p.m.

10

CVSS3.1

CVE-2025-4378 - Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Application

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This issue affects ATA-AOF Mobile Application: before 20.06.2025.

πŸ“… Published: June 24, 2025, 4:27 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.
Total resulsts: 343923
Page 4374 of 34,393
Β« previous page Β» next page
Filters