9.1

CVSS3.1

CVE-2025-28232 -

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 5:17 p.m.

5.4

CVSS3.1

CVE-2024-41447 -

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 5:31 p.m.

9.8

CVSS3.1

CVE-2025-28229 -

Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 5:21 p.m.

3.4

CVSS3.1

CVE-2025-25983 -

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: June 25, 2025, 6:43 p.m.

6.1

CVSS3.1

CVE-2025-29512 -

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 5:28 p.m.

9.1

CVSS3.1

CVE-2025-28230 -

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 5:20 p.m.

9.1

CVSS3.1

CVE-2025-28197 -

Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 7:49 p.m.

4.3

CVSS3.1

CVE-2025-43903 - poppler: SignatureValue not checked within SignerInfo

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 6, 2025, 4:37 p.m.

5.5

CVSS3.1

CVE-2025-37860 - sfc: fix NULL dereferences in ef100_process_design_param()

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run before efx->net_dev is created; consequently, we cannot netif_set_tso_max_size() oโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 2, 2025, 2:15 p.m.

7.8

CVSS3.1

CVE-2025-29625 -

A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 5:13 p.m.
Total resulsts: 346442
Page 5450 of 34,645
ยซ previous page ยป next page
Filters