9.3

CVSS4.0

CVE-2025-4558 - WormHole Tech GPM - Unverified Password Change

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.

πŸ“… Published: May 12, 2025, 3:08 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-4557 - ZONG YU Parking Management System - Missing Authentication

The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.

πŸ“… Published: May 12, 2025, 2:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-4556 - ZONG YU Okcat Parking Management Platform - Arbitrary File Upload

The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

πŸ“… Published: May 12, 2025, 2:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-4562 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: May 12, 2025, 2:02 a.m. πŸ”„ Last Modified: May 22, 2025, 11:15 p.m.

9.3

CVSS4.0

CVE-2025-4555 - ZONG YU Okcat Parking Management Platform - Missing Authentication

The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting…

πŸ“… Published: May 12, 2025, 2:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4554 - PHPGurukul Apartment Visitors Management System bwdates-passreports-details.php sql injection

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-passreports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate …

πŸ“… Published: May 12, 2025, 12:31 a.m. πŸ”„ Last Modified: May 16, 2025, 5:05 p.m.

6.9

CVSS4.0

CVE-2025-4553 - PHPGurukul Apartment Visitors Management System bwdates-reports-details.php sql injection

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may b…

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: May 16, 2025, 5:08 p.m.

6.1

CVSS3.1

CVE-2025-22247 - Insecure file handling vulnerability

VMware Tools contains an insecure file handling vulnerability.Β A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-44175 -

Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 1:39 p.m.

6.5

CVSS3.1

CVE-2024-55466 -

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 1:38 a.m.
Total resulsts: 349182
Page 5463 of 34,919
Β« previous page Β» next page
Filters