8.7

CVSS4.0

CVE-2025-34031 - Moodle LMS Jmol Plugin Path Traversal

A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesyste…

πŸ“… Published: June 24, 2025, 12:58 a.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

2.3

CVSS4.0

CVE-2025-6534 - xxyopen/201206030 novel-plus File FileController.java remove resource injection

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Handler. The manipulation leads to improper con…

πŸ“… Published: June 24, 2025, 12:31 a.m. πŸ”„ Last Modified: July 9, 2025, 7:08 p.m.

6.3

CVSS4.0

CVE-2025-6533 - xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation …

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:48 p.m.

5.3

CVSS4.0

CVE-2025-6532 - NOYAFA/Xiami LF9 Pro RTSP Live Video Stream Endpoint access control

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper access controls. The attack can only be initiated within the lo…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:49 p.m.

7.1

CVSS3.1

CVE-2024-56917 -

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

9.8

CVSS3.1

CVE-2021-41691 -

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

3.6

CVSS3.1

CVE-2025-4878 - Libssh: use of uninitialized variable in privatekey_from_file()

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 7:34 a.m.

4.2

CVSS3.1

CVE-2025-53021 -

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attack…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 3:23 p.m.

9.8

CVSS3.1

CVE-2024-37743 -

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

7.5

CVSS3.1

CVE-2025-44531 -

An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.
Total resulsts: 343968
Page 4387 of 34,397
Β« previous page Β» next page
Filters