4.9

CVSS3.1

CVE-2025-25029 - IBM Security Guardium information disclosure

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

๐Ÿ“… Published: May 28, 2025, 1:12 a.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-25026 - IBM Security Guardium information disclosure

IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

๐Ÿ“… Published: May 28, 2025, 1:11 a.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-25025 - IBM Security Guardium information disclosure

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

๐Ÿ“… Published: May 28, 2025, 1:10 a.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:56 p.m.

7.2

CVSS3.1

CVE-2025-31501 -

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 9, 2025, 6:59 p.m.

4.3

CVSS3.1

CVE-2025-48925 -

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 3:14 p.m.

6.5

CVSS3.1

CVE-2024-57336 -

Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-48746 -

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 6:40 p.m.

3.2

CVSS3.1

CVE-2025-48931 -

The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 2:32 p.m.

7.2

CVSS3.1

CVE-2025-31500 -

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 9, 2025, 6:58 p.m.

4.3

CVSS3.1

CVE-2025-48926 -

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 3:02 p.m.
Total resulsts: 347728
Page 5092 of 34,773
ยซ previous page ยป next page
Filters