5.3

CVSS4.0

CVE-2025-4136 - Weitong Mall Sale Endpoint improper authorization

A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to th…

πŸ“… Published: April 30, 2025, 7:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-2170 -

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.

πŸ“… Published: April 30, 2025, 6:46 p.m. πŸ”„ Last Modified: May 14, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-9877 - Sensitive information submitted using GET method

: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

πŸ“… Published: April 30, 2025, 6:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-9876 - Application is vulnerable to Privilege escalation

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

πŸ“… Published: April 30, 2025, 6:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-46554 - XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki attachment REST endpoint. Th…

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 5:53 p.m.

8.4

CVSS4.0

CVE-2025-46557 - Any user with view access to the XWiki space can change the authenticator

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page XWiki.Authentication.Administrati…

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 5:52 p.m.

9.1

CVSS3.1

CVE-2025-46558 - org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content

XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Markdown syntax is vulnerable to cross-site scripting (XSS) through HTML. In particular, using Markdown syntax, it's possible for…

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:28 p.m.

6.3

CVSS3.1

CVE-2025-24887 - OpenCTI bypass of protected attribute update

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to toggle the `external` flag on/off and change…

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: May 19, 2025, 11:51 a.m.

8.2

CVSS4.0

CVE-2025-32777 - Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin

Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of the scheduler. This is a privilege escalati…

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2025-46331 - OpenFGA Authorization Bypass

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. …

πŸ“… Published: April 30, 2025, 6:27 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 3:06 p.m.
Total resulsts: 349182
Page 5623 of 34,919
Β« previous page Β» next page
Filters