6.8

CVSS4.0

CVE-2025-48741 -

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API end…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2023-34873 -

On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows authenticated users to execute code.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-48702 -

PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-51360 -

An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:15 p.m.

0.0

CVE-2025-48745 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation duplicate of CVE-2025-49113. Notes: All CVE users should reference CVE-2025-49113 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 2, 2025, 1:15 p.m.

6.1

CVSS3.1

CVE-2025-44998 -

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:43 p.m.

6.5

CVSS3.1

CVE-2025-46176 -

Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:47 p.m.

9.8

CVSS3.1

CVE-2024-51101 -

PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:15 p.m.

6.4

CVSS3.1

CVE-2025-48695 -

An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to escalate their privilege by abusing the following API due to the lack of access control: /api/v2/users/user/<user id>/role/ROLE/<Target role> (admin access can be achieved).

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-51102 -

PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:47 p.m.
Total resulsts: 347742
Page 5136 of 34,775
Β« previous page Β» next page
Filters