5.3

CVSS4.0

CVE-2025-6267 - zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 barcodeDetail sql injection

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /adpweb/a/base/barcodeDetail/. The manipulation of the argument barcodeNo/barcode/itemNo leads to sql injection.…

📅 Published: June 19, 2025, 2 p.m. 🔄 Last Modified: Oct. 9, 2025, 4:56 p.m.

6.5

CVSS3.1

CVE-2024-24916 - DLL-HiJacking

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

📅 Published: June 19, 2025, 1:17 p.m. 🔄 Last Modified: Sept. 4, 2025, 7:01 p.m.

9.8

CVSS3.1

CVE-2025-4738 - Authenticated SQLi in Yirmibes Software's MY ERP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software MY ERP allows SQL Injection.This issue affects MY ERP: before 1.170.

📅 Published: June 19, 2025, 12:45 p.m. 🔄 Last Modified: June 23, 2025, 8:16 p.m.

5.3

CVSS4.0

CVE-2025-6266 - Teledyne FLIR AX8 upload.php unrestricted upload

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public an…

📅 Published: June 19, 2025, noon 🔄 Last Modified: Dec. 31, 2025, 5:04 p.m.

6.5

CVSS3.1

CVE-2025-32896 - Apache SeaTunnel: Unauthenticated insecure access

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url to perform Arbitrary File Read and Des…

📅 Published: June 19, 2025, 10:38 a.m. 🔄 Last Modified: July 8, 2025, 1:05 p.m.

7.5

CVSS3.1

CVE-2025-31698 - Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affe…

📅 Published: June 19, 2025, 10:07 a.m. 🔄 Last Modified: July 1, 2025, 8:14 p.m.

7.5

CVSS3.1

CVE-2025-49763 - Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5,…

📅 Published: June 19, 2025, 10:07 a.m. 🔄 Last Modified: July 1, 2025, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-5234 - Gutenverse News <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via elementId P…

The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce…

📅 Published: June 19, 2025, 9:23 a.m. 🔄 Last Modified: April 21, 2026, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-5071 - AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escal…

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access …

📅 Published: June 19, 2025, 9:23 a.m. 🔄 Last Modified: Aug. 11, 2025, 6:11 p.m.

6.4

CVSS3.1

CVE-2025-4965 - WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Build…

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

📅 Published: June 19, 2025, 6:44 a.m. 🔄 Last Modified: April 21, 2026, 8:15 p.m.
Total resulsts: 349182
Page 4954 of 34,919
« previous page » next page
Filters