9.3

CVSS3.1

CVE-2024-58250 -

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-44755 -

Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: June 19, 2025, 12:21 a.m.

6.1

CVSS3.1

CVE-2025-43952 -

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-43948 -

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-44201 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: Aug. 15, 2025, 8:36 p.m.

9.8

CVSS3.1

CVE-2025-43951 -

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-43950 -

DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, th…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-28039 -

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:01 p.m.

9.8

CVSS3.1

CVE-2025-28036 -

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:13 p.m.

9.8

CVSS3.1

CVE-2025-28034 -

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost funct…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:18 p.m.
Total resulsts: 346533
Page 5439 of 34,654
Β« previous page Β» next page
Filters