7.3

CVSS4.0

CVE-2025-5129 - Sangfor 零信任访问控制系统 aTrust MSASN1.dll uncontrolled search path

A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library MSASN1.dll. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The complexity…

📅 Published: May 24, 2025, 4:31 p.m. 🔄 Last Modified: June 17, 2025, 5:54 p.m.

6.9

CVSS4.0

CVE-2025-5128 - ScriptAndTools Real-Estate-website-in-PHP Admin Login Panel admin sql injection

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attac…

📅 Published: May 24, 2025, 4 p.m. 🔄 Last Modified: July 11, 2025, 7:06 p.m.

5.1

CVSS4.0

CVE-2025-5127 - Teledyne FLIR AX8 prod.php cross site scripting

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipulation of the argument cmd can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be u…

📅 Published: May 24, 2025, 3:31 p.m. 🔄 Last Modified: Oct. 15, 2025, 2:15 p.m.

8.7

CVSS4.0

CVE-2025-5126 - Teledyne FLIR AX8 settingsregional.php setDataTime command injection

A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\settingsregional.php. Performing manipulation of the argument year/month/day/hour/minute results in command injection. The attack may be initiate…

📅 Published: May 24, 2025, 3 p.m. 🔄 Last Modified: Oct. 15, 2025, 2:15 p.m.

9.2

CVSS4.0

CVE-2025-5124 - Sony SNC-M1 Administrative Interface default credentials

A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of default credentials. It is possible to initiate …

📅 Published: May 24, 2025, 1 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-4223 - Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting v…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthent…

📅 Published: May 24, 2025, 4:25 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

9.8

CVSS3.1

CVE-2025-5058 - eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_im…

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

📅 Published: May 24, 2025, 3:37 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

8.1

CVSS3.1

CVE-2025-4336 - eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_fi…

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the …

📅 Published: May 24, 2025, 3:37 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

9.1

CVSS3.1

CVE-2025-4603 - eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary file…

📅 Published: May 24, 2025, 3:37 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

5.9

CVSS3.1

CVE-2025-4602 - eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Read

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can conta…

📅 Published: May 24, 2025, 3:37 a.m. 🔄 Last Modified: April 22, 2026, 3 p.m.
Total resulsts: 346002
Page 4943 of 34,601
« previous page » next page
Filters