7.4

CVSS3.1

CVE-2025-52922 -

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

9.9

CVSS3.1

CVE-2025-52921 -

In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uplo…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-48026 -

A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obt…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 2:10 p.m.

9.8

CVSS3.1

CVE-2025-46101 -

SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:58 p.m.

7.5

CVSS3.1

CVE-2025-50348 -

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 1:08 p.m.

9.8

CVSS3.1

CVE-2023-47029 -

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 7:06 p.m.

6.4

CVSS3.1

CVE-2025-52920 -

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

8.4

CVSS4.0

CVE-2025-23049 -

Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 2:11 p.m.

5.8

CVSS3.1

CVE-2025-52967 -

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2023-48978 -

An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:10 p.m.
Total resulsts: 343975
Page 4397 of 34,398
Β« previous page Β» next page
Filters