6.5

CVSS3.1

CVE-2025-47188 -

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parame…

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2023-41519 -

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 2:56 p.m.

5.3

CVSS3.1

CVE-2025-51533 -

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:36 p.m.

6.5

CVSS3.1

CVE-2024-55401 -

An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:37 p.m.

6.5

CVSS3.1

CVE-2025-50952 - openjpeg: Openjpeg NULL pointer dereference

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Dec. 29, 2025, 5:15 p.m.

4.8

CVSS4.0

CVE-2025-48709 - BMC Control-M/Server cleartext database credentials in process lists and logs

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, i…

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:34 p.m.

4.3

CVSS3.1

CVE-2025-54397 -

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Aug. 12, 2025, 7:56 a.m.

8.8

CVSS3.1

CVE-2023-41520 -

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 2:55 p.m.

5.4

CVSS3.1

CVE-2025-54396 -

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: Aug. 12, 2025, 7:56 a.m.

6.4

CVSS3.1

CVE-2025-55133 -

In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.

πŸ“… Published: Aug. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4378 of 34,919
Β« previous page Β» next page
Filters