6.5

CVSS3.1

CVE-2025-29529 -

ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-46417 -

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:39 p.m.

6.5

CVSS3.1

CVE-2025-44134 -

A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.

πŸ“… Published: April 24, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 1:05 p.m.

3.7

CVSS3.1

CVE-2025-25046 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7Β DataStage Flow DesignerΒ  transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

πŸ“… Published: April 23, 2025, 10:24 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 3:04 p.m.

4.3

CVSS3.1

CVE-2025-25045 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.

πŸ“… Published: April 23, 2025, 10:23 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 3:04 p.m.

6.3

CVSS3.1

CVE-2024-22351 - IBM InfoSphere Information Server session fixation

IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: April 23, 2025, 10:15 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:37 a.m.

5.5

CVSS3.1

CVE-2025-46400 - Xfig: fig2dev segmentation fault in read_arcobject

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

5.5

CVSS3.1

CVE-2025-46399 - Xfig: transfig: fig2dev segmentation fault vulnerability

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

5.5

CVSS3.1

CVE-2025-46398 - Xfig: fig2dev stack-overflow via read_objects

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

7.8

CVSS3.1

CVE-2025-46397 - Xfig: xfig: stack-overflow allows possible code execution via local input manipulation

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 4:15 a.m.
Total resulsts: 346667
Page 5433 of 34,667
Β« previous page Β» next page
Filters