7.5

CVSS3.1

CVE-2025-45320 -

A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2025-45237 -

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 7:55 p.m.

6.5

CVSS3.1

CVE-2025-45618 -

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 3:38 p.m.

7.5

CVSS3.1

CVE-2025-45614 -

Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-45609 -

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 7:05 p.m.

9.8

CVSS3.1

CVE-2025-45607 -

An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 8:17 p.m.

7.2

CVSS3.1

CVE-2025-27920 -

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:28 p.m.

6.5

CVSS3.1

CVE-2025-25504 -

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:13 p.m.

6.4

CVSS3.1

CVE-2025-28168 -

The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restricti…

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Sept. 30, 2025, 5:01 p.m.

6.5

CVSS3.1

CVE-2025-26241 -

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 6:38 p.m.
Total resulsts: 349182
Page 5559 of 34,919
Β« previous page Β» next page
Filters