6.8

CVSS3.1

CVE-2025-27892 -

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:30 p.m.

6.5

CVSS3.1

CVE-2020-18243 -

SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo-view-case.php.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 6:43 p.m.

4.6

CVSS3.1

CVE-2025-25453 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:43 p.m.

7.2

CVSS3.1

CVE-2024-50960 -

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 25, 2025, 6:35 p.m.

6

CVSS3.1

CVE-2025-32987 - From CVEorg collector

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.

4.8

CVSS3.1

CVE-2025-29280 -

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 3:19 p.m.

5.5

CVSS3.1

CVE-2025-29213 -

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 25, 2025, 4:49 p.m.

6.5

CVSS3.1

CVE-2025-28145 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: May 1, 2025, 2:26 p.m.

9.1

CVSS3.1

CVE-2021-27289 -

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attack…

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:15 p.m.

5.9

CVSS3.1

CVE-2025-3576 - Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisions

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may …

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Feb. 17, 2026, 7:33 a.m.
Total resulsts: 343048
Page 5272 of 34,305
Β« previous page Β» next page
Filters