8.5

CVSS4.0

CVE-2025-5344 - Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects al…

πŸ“… Published: July 17, 2025, 12:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-5345 - Exposed AIDL service allowing to read and delete files with system-level privileges in Bluebird fil…

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level…

πŸ“… Published: July 17, 2025, 12:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-4302 - Stop User Enumeration < 1.7.3 - Protection Bypass

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

πŸ“… Published: July 17, 2025, 7:37 a.m. πŸ”„ Last Modified: Jan. 23, 2026, 7:30 p.m.

8.7

CVSS4.0

CVE-2025-7735 - UNIMAX|Hospital Information System - SQL Injection

The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

πŸ“… Published: July 17, 2025, 3:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-7712 - Madara - Core <= 2.2.3 - Unauthenticated Arbitrary File Deletion

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, w…

πŸ“… Published: July 17, 2025, 2:24 a.m. πŸ”„ Last Modified: April 20, 2026, 10:15 p.m.

5.1

CVSS4.0

CVE-2025-7729 - Scada-LTS usersProfiles.shtm cross site scripting

A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has be…

πŸ“… Published: July 17, 2025, 2:02 a.m. πŸ”„ Last Modified: Sept. 11, 2025, 3:09 p.m.

9.8

CVSS3.1

CVE-2025-5396 - Bears Backup <= 2.0.0 - Unauthenticated Remote Code Execution

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible f…

πŸ“… Published: July 17, 2025, 1:44 a.m. πŸ”„ Last Modified: April 21, 2026, 7:45 p.m.

5.1

CVSS4.0

CVE-2025-7728 - Scada-LTS users.shtm cross site scripting

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the p…

πŸ“… Published: July 17, 2025, 1:14 a.m. πŸ”„ Last Modified: Sept. 11, 2025, 3:09 p.m.

5.5

CVSS3.1

CVE-2025-51497 -

An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version 1.11.22.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 7:13 p.m.

8.1

CVSS3.1

CVE-2023-41566 -

OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain database permissions.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4610 of 34,919
Β« previous page Β» next page
Filters