9.4

CVSS3.1

CVE-2025-30216 - CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in…

πŸ“… Published: March 25, 2025, 7:22 p.m. πŸ”„ Last Modified: May 6, 2025, 7:34 p.m.

5.9

CVSS3.1

CVE-2024-31896 - IBM SPSS Statistics information disclosure

IBM SPSS StatisticsΒ 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

πŸ“… Published: March 25, 2025, 6:58 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 1:02 a.m.

0.0

CVE-2025-30567 - WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

πŸ“… Published: March 25, 2025, 6:48 p.m. πŸ”„ Last Modified: April 1, 2026, 5:20 p.m.

0.0

CVE-2025-28904 - WordPress Web Directory Free plugin <= 1.7.6 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free allows Blind SQL Injection.This issue affects Web Directory Free: from n/a through <= 1.7.6.

πŸ“… Published: March 25, 2025, 6:48 p.m. πŸ”„ Last Modified: April 1, 2026, 5:19 p.m.

7.3

CVSS3.1

CVE-2024-58105 -

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attack…

πŸ“… Published: March 25, 2025, 5:37 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.3

CVSS3.1

CVE-2024-58104 -

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the …

πŸ“… Published: March 25, 2025, 5:37 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8

CVSS4.0

CVE-2025-30214 - Frappe vulnerable to information disclosure leading to account takeover

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.

πŸ“… Published: March 25, 2025, 3:05 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:28 p.m.

6.3

CVSS4.0

CVE-2025-30213 - Frappe has Possibility of Remote Code Execution due to improper validation

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrad…

πŸ“… Published: March 25, 2025, 2:55 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:29 p.m.

0.0

CVE-2025-26742 - WordPress Gallery for Social Photo plugin <= 1.0.0.35 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35.

πŸ“… Published: March 25, 2025, 2:37 p.m. πŸ”„ Last Modified: April 1, 2026, 5:18 p.m.

8.2

CVSS3.1

CVE-2025-27147 - GLPI Inventory plugin has Improper Access Control Vulnerability

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerabilit…

πŸ“… Published: March 25, 2025, 2:26 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.
Total resulsts: 342301
Page 5529 of 34,231
Β« previous page Β» next page
Filters