4

CVSS3.1

CVE-2025-32803 - Insecure file permissions can result in confidential information leakage

In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.8

CVSS3.1

CVE-2025-48930 -

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 2:43 p.m.

4

CVSS3.1

CVE-2025-48929 -

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 3:01 p.m.

5.3

CVSS3.1

CVE-2025-47748 -

Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 19, 2025, 12:02 a.m.

6.5

CVSS3.1

CVE-2024-57338 -

An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-45343 -

An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 3:36 p.m.

7.2

CVSS3.1

CVE-2025-30087 -

Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

5.3

CVSS3.1

CVE-2025-48927 -

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

6.5

CVSS3.1

CVE-2024-57337 -

An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-32802 - Insecure handling of file paths allows multiple local attacks

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4โ€ฆ

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347725
Page 5093 of 34,773
ยซ previous page ยป next page
Filters