8.2

CVSS4.0

CVE-2025-29998 - No Rate Limiting Vulnerability in CAP back office application

This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/floodin…

📅 Published: March 13, 2025, 11:23 a.m. 🔄 Last Modified: March 13, 2025, 7:33 p.m.

8.2

CVSS4.0

CVE-2025-29997 - Improper Access Control Vulnerability in CAP back office application

This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API request URL to gain unauthorized access to other user accounts.

📅 Published: March 13, 2025, 11:21 a.m. 🔄 Last Modified: March 13, 2025, 7:34 p.m.

8.2

CVSS4.0

CVE-2025-29996 - Authentication Bypass Vulnerability in CAP back office application

This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit this vulnerability by manipulating API request URL/payload. Successful exploitation of this vulner…

📅 Published: March 13, 2025, 11:18 a.m. 🔄 Last Modified: March 13, 2025, 7:36 p.m.

8.3

CVSS4.0

CVE-2025-29995 - Account Takeover Vulnerability in CAP back office application

This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account takeover of targeted …

📅 Published: March 13, 2025, 11:16 a.m. 🔄 Last Modified: March 13, 2025, 7:36 p.m.

8.2

CVSS4.0

CVE-2025-29994 - Improper Authentication Vulnerability in CAP back office application

This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthoriz…

📅 Published: March 13, 2025, 11:12 a.m. 🔄 Last Modified: March 13, 2025, 7:37 p.m.

7.3

CVSS4.0

CVE-2025-25175 -

A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption vulnerability while parsing specially crafted .NEU files. This could allow an attacker to execute code …

📅 Published: March 13, 2025, 9:07 a.m. 🔄 Last Modified: Aug. 19, 2025, 5:36 p.m.

0.0

CVE-2025-2275 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: March 13, 2025, 8:15 a.m. 🔄 Last Modified: March 13, 2025, 11:15 a.m.

5.4

CVSS3.1

CVE-2025-1785 - Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally…

📅 Published: March 13, 2025, 7:31 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

7.3

CVSS3.1

CVE-2025-1119 - Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthentic…

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value b…

📅 Published: March 13, 2025, 6:56 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

7.7

CVSS3.1

CVE-2025-2271 - IDOR in Issuetrak NewAuditID parameter via Inv_PopTrakXShow.asp

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability in the Issuetrak audit component. The vulnerability enables unauthorized access to sensitive informat…

📅 Published: March 13, 2025, 6:30 a.m. 🔄 Last Modified: March 13, 2025, 8:43 p.m.
Total resulsts: 343968
Page 5829 of 34,397
« previous page » next page
Filters