6.3

CVSS3.1

CVE-2025-29405 -

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: March 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 7:35 p.m.

8.3

CVSS3.1

CVE-2024-55551 -

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

πŸ“… Published: March 19, 2025, midnight πŸ”„ Last Modified: Sept. 26, 2025, 4:33 p.m.

2.7

CVSS3.1

CVE-2025-30258 - gnupg: verification DoS due to a malicious subkey in the keyring

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

πŸ“… Published: March 19, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 4:53 p.m.

6.1

CVSS3.1

CVE-2025-30092 -

Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.

πŸ“… Published: March 19, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 2:15 p.m.

6.1

CVSS3.1

CVE-2024-55009 -

A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.

πŸ“… Published: March 19, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 5:45 p.m.

8.8

CVSS3.1

CVE-2024-12563 - s2Member Pro <= 250214 - Authenticated (Contributor+) Local File Inclusion to Remote Code Execution…

The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the serv…

πŸ“… Published: March 18, 2025, 8:21 p.m. πŸ”„ Last Modified: July 12, 2025, 11:05 p.m.

6

CVSS3.1

CVE-2025-27080 - Authenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line Interface

Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to lateral movement invol…

πŸ“… Published: March 18, 2025, 7:02 p.m. πŸ”„ Last Modified: March 18, 2025, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-25042 - Authenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST I…

A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access…

πŸ“… Published: March 18, 2025, 7:02 p.m. πŸ”„ Last Modified: March 18, 2025, 8:15 p.m.

3.3

CVSS3.1

CVE-2025-25040 - Failure to Properly Enforce Port ACLs on CPU generated packets in CX 9300 Switches

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic origina…

πŸ“… Published: March 18, 2025, 6:59 p.m. πŸ”„ Last Modified: March 18, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-29930 - imFAQ allows local file inclusion in seo.php

imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g., seoOp=php://filter/read=convert.base64-encode/resource=/var/www/html/config.php), the application could allow an attacker to …

πŸ“… Published: March 18, 2025, 6:53 p.m. πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.
Total resulsts: 342292
Page 5620 of 34,230
Β« previous page Β» next page
Filters