9.4

CVSS3.0

CVE-2025-8426 - Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-…

Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Marvell QConvergeConsole.…

📅 Published: July 31, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 6, 2025, 4:50 p.m.

6.9

CVSS4.0

CVE-2025-54833 - OPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypass

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.

📅 Published: July 31, 2025, 5:26 p.m. 🔄 Last Modified: Jan. 23, 2026, 2:38 a.m.

6.9

CVSS4.0

CVE-2025-54834 - OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

📅 Published: July 31, 2025, 5:26 p.m. 🔄 Last Modified: Jan. 23, 2026, 2:38 a.m.

5.3

CVSS4.0

CVE-2025-54832 - OPEXUS FOIAXpress Public Access Link (PAL) state and territory list unauthorized modification

OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.

📅 Published: July 31, 2025, 5:25 p.m. 🔄 Last Modified: Jan. 23, 2026, 2:37 a.m.

6.9

CVSS4.0

CVE-2025-8409 - code-projects Vehicle Management filter.php sql injection

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter.php. The manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has b…

📅 Published: July 31, 2025, 3:32 p.m. 🔄 Last Modified: Aug. 5, 2025, 8:59 p.m.

6.9

CVSS4.0

CVE-2025-46809 - Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs

A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1: from ? before…

📅 Published: July 31, 2025, 3:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8408 - code-projects Vehicle Management filter1.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /filter1.php. The manipulation of the argument vehicle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclos…

📅 Published: July 31, 2025, 3:02 p.m. 🔄 Last Modified: Aug. 5, 2025, 8:59 p.m.

9.3

CVSS4.0

CVE-2013-10037 - WebTester 5.x install2.php Unauthenticated Command Execution

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafte…

📅 Published: July 31, 2025, 3:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2014-125126 - Simple E-Document Arbitrary File Upload RCE

An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict file types and does not …

📅 Published: July 31, 2025, 3:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2013-10035 - ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution

A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin. An authenticated user can execute arbitrary PHP code via multiple endpoints, including appFolderAjax.php, casesStartPage_Ajax.php, and cases_SchedulerGetPlugins.php, by supplying…

📅 Published: July 31, 2025, 3 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4445 of 34,919
« previous page » next page
Filters