6.5

CVSS3.1

CVE-2025-27457 - CVE-2025-27457

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

๐Ÿ“… Published: July 3, 2025, 11:32 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

7.5

CVSS3.1

CVE-2025-27456 - CVE-2025-27456

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

๐Ÿ“… Published: July 3, 2025, 11:32 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

4.3

CVSS3.1

CVE-2025-27455 - CVE-2025-27455

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of tโ€ฆ

๐Ÿ“… Published: July 3, 2025, 11:30 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

4.3

CVSS3.1

CVE-2025-27454 - CVE-2025-27454

The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's browser's saved authorization to execute the request.

๐Ÿ“… Published: July 3, 2025, 11:30 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

5.3

CVSS3.1

CVE-2025-27453 - CVE-2025-27453

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

๐Ÿ“… Published: July 3, 2025, 11:29 a.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 6:02 p.m.

5.3

CVSS3.1

CVE-2025-27452 - CVE-2025-27452

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the webserver which enable dโ€ฆ

๐Ÿ“… Published: July 3, 2025, 11:29 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:38 p.m.

5.3

CVSS3.1

CVE-2025-27451 - CVE-2025-27451

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

๐Ÿ“… Published: July 3, 2025, 11:27 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:38 p.m.

6.5

CVSS3.1

CVE-2025-27450 - CVE-2025-27450

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

๐Ÿ“… Published: July 3, 2025, 11:26 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:38 p.m.

7.5

CVSS3.1

CVE-2025-27449 - CVE-2025-27449

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

๐Ÿ“… Published: July 3, 2025, 11:25 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:38 p.m.

6.8

CVSS3.1

CVE-2025-27448 - CVE-2025-27448

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.

๐Ÿ“… Published: July 3, 2025, 11:24 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:38 p.m.
Total resulsts: 349182
Page 4803 of 34,919
ยซ previous page ยป next page
Filters