9

CVSS3.1

CVE-2025-54309 -

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:25 p.m.

7.8

CVSS3.1

CVE-2025-38349 - eventpoll: don't decrement ep refcount while still holding the ep mutex

In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points out that epoll is decrementing the ep refcount and then doing a mutex_unlock(&ep->mtx); afterwards. That's very wrong, because it can โ€ฆ

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

8.8

CVSS3.1

CVE-2025-50585 -

StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 9, 2025, 7:22 p.m.

6.5

CVSS3.1

CVE-2025-52168 -

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-46001 -

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 2:28 p.m.

6.5

CVSS3.1

CVE-2025-46000 -

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 2:15 p.m.

7.1

CVSS3.1

CVE-2025-52169 -

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-50586 -

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 9, 2025, 7:23 p.m.

4.8

CVSS3.1

CVE-2025-50581 -

MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:04 p.m.

6.5

CVSS3.1

CVE-2025-45157 -

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

๐Ÿ“… Published: July 18, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 6:44 p.m.
Total resulsts: 348147
Page 4498 of 34,815
ยซ previous page ยป next page
Filters