6.5

CVSS3.1

CVE-2025-48746 -

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 6:40 p.m.

3.2

CVSS3.1

CVE-2025-48931 -

The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 2:32 p.m.

7.2

CVSS3.1

CVE-2025-31500 -

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 9, 2025, 6:58 p.m.

4.3

CVSS3.1

CVE-2025-48926 -

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 3:02 p.m.

4

CVSS3.1

CVE-2025-48928 -

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

8.6

CVSS3.1

CVE-2025-45997 -

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 9, 2025, 6:53 p.m.

5

CVSS3.1

CVE-2025-48747 -

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 19, 2025, 12:01 a.m.

4

CVSS3.1

CVE-2025-32803 - Insecure file permissions can result in confidential information leakage

In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.8

CVSS3.1

CVE-2025-48930 -

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 2:43 p.m.

4

CVSS3.1

CVE-2025-48929 -

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 22, 2025, 3:01 p.m.
Total resulsts: 349182
Page 5238 of 34,919
ยซ previous page ยป next page
Filters