9.8

CVSS3.1

CVE-2023-47031 -

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2023-47030 -

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

7.4

CVSS3.1

CVE-2025-52922 -

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-50349 -

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

5.8

CVSS3.1

CVE-2025-52967 -

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-52969 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 4:15 p.m.

8.1

CVSS3.1

CVE-2023-47294 -

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 7:10 p.m.

7.5

CVSS3.1

CVE-2025-48026 -

A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obt…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-48700 - Cross‑Site Scripting via Crafted Emails in Zimbra Classic UI

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information…

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 22, 2026, 12:15 p.m.

7.5

CVSS3.1

CVE-2025-44528 -

An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a crafted LL_Pause_Enc_Req packet during the authentication and connection phase, causing a Denial of Service (DoS).

πŸ“… Published: June 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4918 of 34,919
Β« previous page Β» next page
Filters