6

CVSS4.0

CVE-2025-5087 - Cleartext Transmission of Sensitive Information in Kaleris Navis N4

Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traffic between Ultra Light Clients and N4 servers can extract sensitive information, including plaintext credentials.

πŸ“… Published: June 24, 2025, 6:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-2566 - Deserialization of Untrusted Data in Kaleris Navis N4

Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.

πŸ“… Published: June 24, 2025, 6:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-49147 - Umbraco.Cms Vulnerable to Disclosure of Configured Password Requirements

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously authenticated endpoint it's possible to retrieve information about the configured password requirements. The information …

πŸ“… Published: June 24, 2025, 5:37 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 1:53 p.m.

5

CVSS3.1

CVE-2025-23260 -

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.

πŸ“… Published: June 24, 2025, 5:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:50 p.m.

10

CVSS3.1

CVE-2025-4378 - Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Application

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This issue affects ATA-AOF Mobile Application: before 20.06.2025.

πŸ“… Published: June 24, 2025, 4:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6570 - PHPGurukul Hospital Management System search.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotel…

πŸ“… Published: June 24, 2025, 3:31 p.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

7.8

CVSS3.1

CVE-2025-23265 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tamp…

πŸ“… Published: June 24, 2025, 3:29 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 7:44 p.m.

7.8

CVSS3.1

CVE-2025-23264 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tamp…

πŸ“… Published: June 24, 2025, 3:21 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 7:44 p.m.

9.3

CVSS3.1

CVE-2025-4383 - Authentication Bypass in Art-In Systems' Wi-Fi Cloud Hotspot

Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass.This issue affects Wi-Fi Cloud Hotspot: before 30.05.2025.

πŸ“… Published: June 24, 2025, 3:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6569 - code-projects School Fees Payment System student.php cross site scripting

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vulnerability is an unknown functionality of the file /student.php. The manipulation of the argument sname/contact/about/emailid/transcation_remark leads to cross site scripting. Th…

πŸ“… Published: June 24, 2025, 3 p.m. πŸ”„ Last Modified: July 11, 2025, 3:54 p.m.
Total resulsts: 349182
Page 4900 of 34,919
Β« previous page Β» next page
Filters