6.8

CVSS3.1

CVE-2025-49544 - ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information or byp…

📅 Published: July 8, 2025, 8:49 p.m. 🔄 Last Modified: July 13, 2025, 9:08 p.m.

4.3

CVSS3.1

CVE-2025-49543 - ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

📅 Published: July 8, 2025, 8:49 p.m. 🔄 Last Modified: July 13, 2025, 9:08 p.m.

4.3

CVSS3.1

CVE-2025-49540 - ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

📅 Published: July 8, 2025, 8:49 p.m. 🔄 Last Modified: July 13, 2025, 9:08 p.m.

7.4

CVSS3.1

CVE-2025-49538 - ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91)

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation…

📅 Published: July 8, 2025, 8:49 p.m. 🔄 Last Modified: July 13, 2025, 9:47 p.m.

8.7

CVSS4.0

CVE-2025-7194 - D-Link DI-500WF jhttpd ip_position.asp sprintf stack-based overflow

A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file ip_position.asp of the component jhttpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be launche…

📅 Published: July 8, 2025, 8:32 p.m. 🔄 Last Modified: July 14, 2025, 3:14 p.m.

6.9

CVSS4.0

CVE-2025-7193 - itsourcecode Agri-Trading Online Shopping System suppliercontroller.php sql injection

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql injection. It is possible to launch the atta…

📅 Published: July 8, 2025, 8:02 p.m. 🔄 Last Modified: July 11, 2025, 6:44 p.m.

7.5

CVSS3.1

CVE-2025-53355 - mcp-server-kubernetes vulnerable to command injection in several tools

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling a…

📅 Published: July 8, 2025, 7:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7192 - D-Link DIR-645 ssdpcgi cgibin ssdpcgi_main command injection

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed t…

📅 Published: July 8, 2025, 7:32 p.m. 🔄 Last Modified: July 14, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2025-37103 - Hardcoded Credential Exposure Allows Unauthorized Access in Web Interface

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

📅 Published: July 8, 2025, 7:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-37102 - Authenticated Command Injection Vulnerability In Instant On Command Line Interface

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privile…

📅 Published: July 8, 2025, 7:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4720 of 34,919
« previous page » next page
Filters