5.3

CVSS3.1

CVE-2025-51308 -

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:35 p.m.

6.1

CVSS3.1

CVE-2025-50740 -

AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web interface /_ac/config allows HTML/JS code to be executed via a crafted network SSID.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-46660 -

An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:37 p.m.

6.5

CVSS3.1

CVE-2024-55399 -

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:35 p.m.

5.3

CVSS3.1

CVE-2024-55402 -

4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:37 p.m.

6.5

CVSS3.1

CVE-2024-55398 -

4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:38 p.m.

8.1

CVSS3.1

CVE-2025-50286 -

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 7, 2025, 7:18 p.m.

6.5

CVSS3.1

CVE-2025-51057 -

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:36 p.m.

6.5

CVSS3.1

CVE-2025-51052 -

A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:35 p.m.

8.6

CVSS3.1

CVE-2025-51055 -

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:36 p.m.
Total resulsts: 349182
Page 4402 of 34,919
ยซ previous page ยป next page
Filters