1.1

CVSS4.0

CVE-2024-51991 - October CMS Allows Unprotected SVG Rename in Media Manager

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vuln…

πŸ“… Published: May 5, 2025, 5:04 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 6:54 p.m.

7.3

CVSS4.0

CVE-2025-0217 - Privileged Remote Access Authentication Bypass

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.

πŸ“… Published: May 5, 2025, 5 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2025-1992 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

πŸ“… Published: May 5, 2025, 4:54 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2024-11615 - Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions. This is due to the plugin not properly validating a file or its path prior to deleting it. This makes …

πŸ“… Published: May 5, 2025, 4:21 p.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

5.3

CVSS4.0

CVE-2025-4281 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclo…

A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack r…

πŸ“… Published: May 5, 2025, 4 p.m. πŸ”„ Last Modified: May 5, 2025, 8:54 p.m.

4.3

CVSS3.1

CVE-2025-4316 -

Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through 2025.1.6.0, and all versions…

πŸ“… Published: May 5, 2025, 2 p.m. πŸ”„ Last Modified: June 17, 2025, 2:13 p.m.

2.3

CVSS4.0

CVE-2025-2545 - Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could comp…

πŸ“… Published: May 5, 2025, 11:28 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.3

CVSS4.0

CVE-2025-4272 - Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation lea…

πŸ“… Published: May 5, 2025, 11 a.m. πŸ”„ Last Modified: May 5, 2025, 8:54 p.m.

9.1

CVSS3.1

CVE-2025-2905 - An XML External Entity (XXE) vulnerability in Multiple WSO2 Products

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read sensitive files from …

πŸ“… Published: May 5, 2025, 9:02 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 12:15 p.m.

6.9

CVSS4.0

CVE-2025-4271 - TOTOLINK A720R cstecgi.cgi information disclosure

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to information disclosure. The attack …

πŸ“… Published: May 5, 2025, 8 a.m. πŸ”„ Last Modified: May 7, 2025, 4:38 p.m.
Total resulsts: 343761
Page 5010 of 34,377
Β« previous page Β» next page
Filters