7.1

CVSS3.1

CVE-2025-33137 - IBM Aspera Faspex data modification

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

πŸ“… Published: May 22, 2025, 4:36 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 3:05 p.m.

7.1

CVSS3.1

CVE-2025-33136 - IBM Aspera Faspex data modification

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

πŸ“… Published: May 22, 2025, 4:14 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 3:04 p.m.

7.4

CVSS4.0

CVE-2025-4366 - Request Smuggling Vulnerability in Pingora

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in:Β  https://github.com/cloudf…

πŸ“… Published: May 22, 2025, 3:50 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 5:01 p.m.

6.1

CVSS3.1

CVE-2025-23183 - UBtech – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

πŸ“… Published: May 22, 2025, 3:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5081 - Campcodes Cybercafe Management System adminprofile.php sql injection

A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: May 22, 2025, 3:31 p.m. πŸ”„ Last Modified: May 28, 2025, 1:49 a.m.

4.3

CVSS3.1

CVE-2025-23182 - UBtech – CWE-203: Observable Discrepancy

CWE-203: Observable Discrepancy

πŸ“… Published: May 22, 2025, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-2506 -

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read access to replicated tables. When pglogical runs it should verify it i…

πŸ“… Published: May 22, 2025, 3:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-5080 - Tenda FH451 webExcptypemanFilter stack-based overflow

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit…

πŸ“… Published: May 22, 2025, 3 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

6.8

CVSS3.1

CVE-2024-12093 - Improper Validation of Consistency within Input in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

πŸ“… Published: May 22, 2025, 2:32 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:37 p.m.

4.6

CVSS3.1

CVE-2025-0605 - Weak Authentication in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

πŸ“… Published: May 22, 2025, 2:31 p.m. πŸ”„ Last Modified: May 29, 2025, 3:58 p.m.
Total resulsts: 349182
Page 5287 of 34,919
Β« previous page Β» next page
Filters