6.9

CVSS4.0

CVE-2025-4239 - PCMan FTP Server TYPE Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component TYPE Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and mayโ€ฆ

๐Ÿ“… Published: May 3, 2025, 5 p.m. ๐Ÿ”„ Last Modified: May 16, 2025, 5:40 p.m.

4.3

CVSS3.1

CVE-2025-1495 - IBM Business Automation Workflow missing authentication

IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.

๐Ÿ“… Published: May 3, 2025, 4:53 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 2:28 p.m.

6.9

CVSS4.0

CVE-2025-4238 - PCMan FTP Server MGET Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component MGET Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and maโ€ฆ

๐Ÿ“… Published: May 3, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: May 16, 2025, 5:31 p.m.

8.1

CVSS3.1

CVE-2024-58134 - Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class naโ€ฆ

Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies.ย  An attacker who knows or guesses the secret could computeโ€ฆ

๐Ÿ“… Published: May 3, 2025, 4:08 p.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 8:15 p.m.

6.1

CVSS3.1

CVE-2024-41753 - IBM Cloud Pak for Business Automation cross-site scripting

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadinโ€ฆ

๐Ÿ“… Published: May 3, 2025, 4:06 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 2:28 p.m.

6.9

CVSS4.0

CVE-2025-4237 - PCMan FTP Server MDELETE Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the publicโ€ฆ

๐Ÿ“… Published: May 3, 2025, 3 p.m. ๐Ÿ”„ Last Modified: May 16, 2025, 3:03 p.m.

6.9

CVSS4.0

CVE-2025-4236 - PCMan FTP Server MDIR Command buffer overflow

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to thโ€ฆ

๐Ÿ“… Published: May 3, 2025, 2 p.m. ๐Ÿ”„ Last Modified: May 16, 2025, 3:04 p.m.

6.9

CVSS4.0

CVE-2025-4226 - PHPGurukul/Campcodes Cyber Cafe Management System add-computer.php sql injection

A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is possible to initiate the attack remotely. The eโ€ฆ

๐Ÿ“… Published: May 3, 2025, 11 a.m. ๐Ÿ”„ Last Modified: May 30, 2025, 10:15 a.m.

5.3

CVSS3.1

CVE-2024-58135 - Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo geโ€ฆ

Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, andโ€ฆ

๐Ÿ“… Published: May 3, 2025, 10:16 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-3815 - SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜idโ€™ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and aboveโ€ฆ

๐Ÿ“… Published: May 3, 2025, 7:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:20 p.m.
Total resulsts: 343887
Page 5032 of 34,389
ยซ previous page ยป next page
Filters