0.0

CVE-2025-53746 -

Not used

📅 Published: July 9, 2025, 9:40 a.m. 🔄 Last Modified: July 10, 2025, 2:55 a.m.

10

CVSS3.1

CVE-2025-3499 - Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart Collector

The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system.

📅 Published: July 9, 2025, 8:57 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-3498 - Unauthenticated modification of Radiflow iSAP Smart Collector configuration

An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these API…

📅 Published: July 9, 2025, 8:53 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-3497 - Radiflow iSAP Smart Collector Linux distribution unmaintained

The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.

📅 Published: July 9, 2025, 8:46 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-27028 - Read access of deprivileged Radiflow iSAP Smart Collector user

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).

📅 Published: July 9, 2025, 8:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2025-27027 - Restricted shell evasion in Radiflow iSAP Smart Collector

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.

📅 Published: July 9, 2025, 8:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-7379 - A security bypass vulnerability was found in DataSync Center installed on ADM

A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Center: from 1.1.0 before 1.1.0.r207, and from 1.2.…

📅 Published: July 9, 2025, 8:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2025-7378 - An improper input validation vulnerability was found on manipulating configuration of ADM

An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior. This issue affects ADM: fr…

📅 Published: July 9, 2025, 7:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-32990 - Gnutls: vulnerability in gnutls certtool template parsing

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a de…

📅 Published: July 9, 2025, 7 a.m. 🔄 Last Modified: April 20, 2026, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-7220 - Campcodes Payroll Management System ajax.php sql injection

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_deductions. The manipulation of the argument ID leads to sql injection. The attack can be launched rem…

📅 Published: July 9, 2025, 6:32 a.m. 🔄 Last Modified: July 13, 2025, 9:08 p.m.
Total resulsts: 347943
Page 4583 of 34,795
« previous page » next page
Filters