8.5

CVSS4.0

CVE-2025-2858 - Privilege escalation vulnerability in saTECH BCU

Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the device could make use of the nice command to bypass all restrictions and elevate privileges as a superuser.

📅 Published: March 28, 2025, 1:08 p.m. 🔄 Last Modified: Oct. 15, 2025, 4:52 p.m.

5.3

CVSS4.0

CVE-2025-2911 - Improper Restriction of Excessive Authentication Attempts vulnerability in MeetMe products

Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an attacker to identify multiple users and perform brute force attacks via extensions.

📅 Published: March 28, 2025, 12:54 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

8.2

CVSS4.0

CVE-2024-7407 - Weak password encoding in Streamsoft Prestiż

Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.…

📅 Published: March 28, 2025, 12:54 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

8.6

CVSS4.0

CVE-2024-11504 - SQL Injection in Streamsoft Prestiż

Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker.  This issue was fixed in 18.1.376.37 version of the software.

📅 Published: March 28, 2025, 12:54 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

6.9

CVSS4.0

CVE-2025-2910 - User enumeration vulnerability in MeetMe products

User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.

📅 Published: March 28, 2025, 12:53 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

6.9

CVSS4.0

CVE-2025-2909 - Lack of encryption vulnerability in DuoxMe

The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

📅 Published: March 28, 2025, 12:51 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

8.5

CVSS4.0

CVE-2025-2908 - Insufficiently Protected Credentials vulnerability in MeetMe products

The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.

📅 Published: March 28, 2025, 12:32 p.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

0.0

CVE-2025-31432 - WordPress Pop-Up Chop Chop plugin <= 2.1.7 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Chop Chop Pop-Up Chop Chop pop-up allows PHP Local File Inclusion.This issue affects Pop-Up Chop Chop: from n/a through <= 2.1.7.

📅 Published: March 28, 2025, 11:54 a.m. 🔄 Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31433 - WordPress Magic Embeds plugin <= 3.1.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Miguel Sirvent Magic Embeds wp-embed-facebook allows Stored XSS.This issue affects Magic Embeds: from n/a through <= 3.1.2.

📅 Published: March 28, 2025, 11:54 a.m. 🔄 Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31434 - WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.19 - Cross Site Scripting (XSS) Vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms formlift allows Stored XSS.This issue affects FormLift for Infusionsoft Web Forms: from n/a through <= 7.5.19.

📅 Published: March 28, 2025, 11:54 a.m. 🔄 Last Modified: April 1, 2026, 5:21 p.m.
Total resulsts: 343924
Page 5621 of 34,393
« previous page » next page
Filters