4.8

CVSS4.0

CVE-2025-8521 - givanz Vvveb Add Type post-types cross site scripting

A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects some unknown processing of the file /vadmin123/index.php?module=settings/post-types of the component Add Type Handler. The manipulation leads to cross site scripting. The attack may …

πŸ“… Published: Aug. 4, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:21 p.m.

7.5

CVSS3.1

CVE-2025-38741 -

Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

πŸ“… Published: Aug. 4, 2025, 6:22 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 5:57 p.m.

9.3

CVSS4.0

CVE-2013-10054 - LibrettoCMS File Manager Arbitrary File Upload

An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails …

πŸ“… Published: Aug. 4, 2025, 6:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2013-10052 - ZPanel zsudo Local Privilege Escalation

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged usersΒ to execute arbitrary commands as root. This flaw enables local attackers with shell acce…

πŸ“… Published: Aug. 4, 2025, 6:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8520 - givanz Vvveb Drag-and-Drop Editor editor server-side request forgery

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to server-side request forgery. The attack can be init…

πŸ“… Published: Aug. 4, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:21 p.m.

9.4

CVSS4.0

CVE-2025-34147 - Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via SSID

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-time shell script. This allows remote attack…

πŸ“… Published: Aug. 4, 2025, 5:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8519 - givanz Vvveb Drag-and-Drop Editor editor information disclosure

A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of the file /vadmin123/index.php?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to information disclosure. It is possible to ini…

πŸ“… Published: Aug. 4, 2025, 5:32 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:21 p.m.

5.1

CVSS4.0

CVE-2025-8518 - givanz Vvveb Code Editor code.php save code injection

A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin/controller/editor/code.php of the component Code Editor. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been …

πŸ“… Published: Aug. 4, 2025, 5:02 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:22 p.m.

5.3

CVSS4.0

CVE-2025-8517 - givanz Vvveb session fixiation

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identif…

πŸ“… Published: Aug. 4, 2025, 4:02 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:23 p.m.

7.2

CVSS3.1

CVE-2025-38739 -

Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to Information Disclosure.

πŸ“… Published: Aug. 4, 2025, 3:53 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 3:41 p.m.
Total resulsts: 349182
Page 4418 of 34,919
Β« previous page Β» next page
Filters