8.1

CVSS3.1

CVE-2024-32323 -

SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information via the if parameter in hcit.project.rte.agents.UploadImages.class.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2023-47356 -

Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2025-53964 -

GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then searches for any term included in that dictionary.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 4:43 p.m.

9.8

CVSS3.1

CVE-2025-51630 -

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: July 18, 2025, 5:25 p.m.

9.8

CVSS3.1

CVE-2025-52046 -

Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: Sept. 26, 2025, 1:09 p.m.

6.1

CVSS3.1

CVE-2025-47189 -

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-53867 -

Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46102 -

Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 2:37 p.m.

4.4

CVSS3.1

CVE-2025-7738 - Python3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in a…

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users…

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-50240 -

nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteRecycleBin.

πŸ“… Published: July 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4611 of 34,919
Β« previous page Β» next page
Filters