2.3

CVSS4.0

CVE-2025-6527 - 70mai M300 Web Server access control

A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown function of the component Web Server. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The complexity of an attack is ra…

πŸ“… Published: June 23, 2025, 10 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 2:46 p.m.

2.3

CVSS4.0

CVE-2025-6526 - 70mai M300 HTTP Server insufficiently protected credentials

A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the component HTTP Server. The manipulation leads to insufficiently protected credentials. The attack can only be done within the local network. The compl…

πŸ“… Published: June 23, 2025, 10 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 3:02 p.m.

5.3

CVSS4.0

CVE-2025-6525 - 70mai 1S Configuration Config.cgi improper authorization

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component Configuration Handler. The manipulation leads to improper authorization. The attack needs to be approached within the l…

πŸ“… Published: June 23, 2025, 9:31 p.m. πŸ”„ Last Modified: June 27, 2025, 2:10 p.m.

6.9

CVSS4.0

CVE-2025-52561 - HTMLSanitizer.jl Possible XSS

HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist, content inside the tag is incorrectly unescaped, and closing tags injected as content are interpreted as real HTML, enabling tag injection and JavaScript execution. This could r…

πŸ“… Published: June 23, 2025, 9 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

2.3

CVSS4.0

CVE-2025-6524 - 70mai 1S Video Services improper authentication

A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the component Video Services. The manipulation leads to improper authentication. Access to the local network is required for this attack to succeed. The complexity of an attack is ra…

πŸ“… Published: June 23, 2025, 9 p.m. πŸ”„ Last Modified: June 27, 2025, 2:10 p.m.

7

CVSS4.0

CVE-2025-52558 - ChangeDetection.io XSS in watch overview

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS) vulnerability. This …

πŸ“… Published: June 23, 2025, 8:52 p.m. πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

10

CVSS3.1

CVE-2025-52562 - Convey Panel Directory Traversal in LocaleController leading to Remote Code Execution

Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Convoy. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafte…

πŸ“… Published: June 23, 2025, 8:48 p.m. πŸ”„ Last Modified: July 14, 2025, 11:06 p.m.

10.0

CVSS3.1

CVE-2025-2828 - SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit do…

πŸ“… Published: June 23, 2025, 8:42 p.m. πŸ”„ Last Modified: July 16, 2025, 7:46 p.m.

6.4

CVSS3.1

CVE-2025-49574 - Quarkus potential data leak when duplicating a duplicated context

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation.…

πŸ“… Published: June 23, 2025, 7:47 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 7:15 p.m.

7.3

CVSS3.1

CVE-2025-49144 - Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social en…

πŸ“… Published: June 23, 2025, 7:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 343975
Page 4391 of 34,398
Β« previous page Β» next page
Filters