8

CVSS3.1

CVE-2025-50849 -

CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the server side. An authenticated user can manipul…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-50848 -

A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious con…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:35 p.m.

7

CVSS3.1

CVE-2025-45768 - pyjwt: pyjwt Weak Encryption Vulnerability

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 4:45 p.m.

7.3

CVSS3.1

CVE-2025-29556 -

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation process allows an a…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-26062 -

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

5.4

CVSS3.1

CVE-2025-29557 -

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-26063 -

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

6.1

CVSS3.1

CVE-2025-51569 -

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers t…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-45770 -

jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to…

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: Aug. 17, 2025, 4:15 a.m.

6.1

CVSS3.1

CVE-2025-50270 -

A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.

πŸ“… Published: July 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4454 of 34,919
Β« previous page Β» next page
Filters