9.9

CVSS3.1

CVE-2025-52921 -

In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uplo…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-48978 -

An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:10 p.m.

8.4

CVSS4.0

CVE-2025-23049 -

Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-50348 -

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 1:08 p.m.

9.8

CVSS3.1

CVE-2023-47297 -

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2025-46101 -

SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:58 p.m.

9.8

CVSS3.1

CVE-2023-47295 -

A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2023-47031 -

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2023-47030 -

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

7.4

CVSS3.1

CVE-2025-52922 -

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348489
Page 4848 of 34,849
Β« previous page Β» next page
Filters