4.1

CVSS3.1

CVE-2025-27907 - IBM WebSphere Application Server server-side request forgery

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: April 22, 2025, 4:20 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:38 a.m.

7.6

CVSS3.1

CVE-2025-23251 -

NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:42 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.6

CVSS3.1

CVE-2025-23250 -

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:35 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.6

CVSS3.1

CVE-2025-23249 -

NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.2

CVSS3.1

CVE-2025-3767 - SQL Injection in Centreon BAM boolean KPI listing

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM: from 24.10 before 24.1…

πŸ“… Published: April 22, 2025, 3:16 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

8.4

CVSS3.1

CVE-2025-1951 - IBM Hardware Management Console - Power Systems command execution

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.

πŸ“… Published: April 22, 2025, 2:48 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

9.3

CVSS3.1

CVE-2025-1950 - IBM Hardware Management Console - Power Systems command execution

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.

πŸ“… Published: April 22, 2025, 2:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2025-23176 - Tecnick – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti…

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

πŸ“… Published: April 22, 2025, 2:23 p.m. πŸ”„ Last Modified: June 20, 2025, 1:55 p.m.

6.1

CVSS3.1

CVE-2025-23175 - Tecnick - Multiple XSS (CWE-79)

Multiple XSS (CWE-79)

πŸ“… Published: April 22, 2025, 12:24 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.1

CVSS4.0

CVE-2025-2092 - Remote site authentication secrets written to web log

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.

πŸ“… Published: April 22, 2025, 11:38 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 1:26 a.m.
Total resulsts: 343948
Page 5172 of 34,395
Β« previous page Β» next page
Filters