8.2

CVSS3.1

CVE-2025-44137 -

MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web se…

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 9:16 p.m.

7.5

CVSS3.1

CVE-2024-42644 -

FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0.

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 8:48 p.m.

9.8

CVSS3.1

CVE-2025-44136 -

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 8:47 p.m.

7.5

CVSS3.1

CVE-2024-42651 -

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:40 p.m.

6.4

CVSS3.1

CVE-2024-43018 -

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in ad…

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 4:24 p.m.

6.5

CVSS3.1

CVE-2025-51044 -

phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testing.php file, due to insufficient validation of user input for the " govtissuedid" parameter.

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 5:52 p.m.

9.8

CVSS3.1

CVE-2025-50738 -

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be explo…

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 22, 2025, 4:15 p.m.

7.7

CVSS3.1

CVE-2025-51970 -

A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:08 p.m.

6.5

CVSS3.1

CVE-2025-28172 -

Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force atta…

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 8:53 p.m.

6.3

CVSS3.1

CVE-2025-52358 -

A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser…

πŸ“… Published: July 29, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 8:53 p.m.
Total resulsts: 349182
Page 4482 of 34,919
Β« previous page Β» next page
Filters