6.1

CVSS3.1

CVE-2025-51857 -

The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-50454 -

An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the application as an administrator without valid credentials.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-46658 -

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 2, 2025, 5:38 p.m.

7.4

CVSS3.1

CVE-2025-43979 -

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands with root privileges via crafted payloads to the xml_action.cgi?method= endpoint.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-51541 -

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to inject malicious Javโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 10, 2025, 3:30 p.m.

9.8

CVSS3.1

CVE-2025-50707 -

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 14, 2025, 4:08 p.m.

7.5

CVSS3.1

CVE-2025-51628 -

Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-50688 -

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uplโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2025, 6:35 p.m.

9.8

CVSS3.1

CVE-2025-50706 -

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 14, 2025, 4:08 p.m.

7.4

CVSS3.1

CVE-2025-43978 -

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with rโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4415 of 34,919
ยซ previous page ยป next page
Filters