7.2

CVSS4.0

CVE-2025-2297 - Privilege Management for Windows - Elevation of Privilege

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to admini…

πŸ“… Published: July 28, 2025, 3:40 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 1:46 p.m.

5.4

CVSS3.1

CVE-2024-49343 - IBM Informix Dynamic Server HTML injection

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

πŸ“… Published: July 28, 2025, 3:27 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 5:12 p.m.

7.5

CVSS3.1

CVE-2024-49342 - IBM Informix Dynamic Server information disclosure

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

πŸ“… Published: July 28, 2025, 3:26 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 5:13 p.m.

9.8

CVSS3.1

CVE-2025-54418 - CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image processing (`imagick` as the image library) and either allow file uploads with user-controlled filenames and process up…

πŸ“… Published: July 28, 2025, 2:47 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:46 p.m.

9.3

CVSS4.0

CVE-2025-53696 -

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.

πŸ“… Published: July 28, 2025, 2:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-53695 -

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.

πŸ“… Published: July 28, 2025, 2:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-8279 - Missing Authentication for Critical Function in GitLab Language Server

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

πŸ“… Published: July 28, 2025, 2:04 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 6:59 p.m.

9.3

CVSS3.1

CVE-2025-26469 -

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a configuration-related registry key. An attacker can execute a malicious script or a…

πŸ“… Published: July 28, 2025, 1:36 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

9.3

CVSS3.1

CVE-2025-27724 -

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. An attacker can upload a malicious file to trigger this vulnerability.

πŸ“… Published: July 28, 2025, 1:36 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

6.1

CVSS3.1

CVE-2025-32731 -

A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerabilit…

πŸ“… Published: July 28, 2025, 1:36 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.
Total resulsts: 349182
Page 4486 of 34,919
Β« previous page Β» next page
Filters