5.6

CVSS3.1

CVE-2025-27867 - Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the iss…

📅 Published: March 12, 2025, 3:51 p.m. 🔄 Last Modified: July 16, 2025, 6:09 p.m.

9.8

CVSS3.1

CVE-2025-1960 -

CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly in the WebHMI interface.

📅 Published: March 12, 2025, 3:33 p.m. 🔄 Last Modified: March 13, 2025, 7:15 p.m.

7

CVSS4.0

CVE-2025-0813 -

CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.

📅 Published: March 12, 2025, 3:30 p.m. 🔄 Last Modified: March 12, 2025, 4:15 p.m.

5.2

CVSS3.1

CVE-2025-1984 - Local Privilege Escalation on Xerox® Desktop Print Experience® v8.5

Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.

📅 Published: March 12, 2025, 3:27 p.m. 🔄 Last Modified: May 12, 2025, 3:37 p.m.

7.8

CVSS3.1

CVE-2025-1683 - Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.

📅 Published: March 12, 2025, 3:25 p.m. 🔄 Last Modified: Jan. 30, 2026, 4:36 p.m.

4

CVSS4.0

CVE-2025-2002 -

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.

📅 Published: March 12, 2025, 3:25 p.m. 🔄 Last Modified: May 12, 2025, 3:37 p.m.

2.1

CVSS4.0

CVE-2025-0883 - vulnerability has been discovered in OpenText™ Service Manager.

Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager.  The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80.

📅 Published: March 12, 2025, 3:24 p.m. 🔄 Last Modified: May 12, 2025, 3:35 p.m.

7.3

CVSS4.0

CVE-2025-0884 - Privilege Escalation vulnerability has been discovered in OpenText™ Service Manager.

Unquoted Search Path or Element vulnerability in OpenText™ Service Manager.  The vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation. This issue affects Service Manager: 9.70, 9.71, 9.72.

📅 Published: March 12, 2025, 3:24 p.m. 🔄 Last Modified: May 12, 2025, 3:36 p.m.

4.8

CVSS3.1

CVE-2025-29891 - Apache Camel: Camel Message Header Injection through request parameters

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability i…

📅 Published: March 12, 2025, 2:42 p.m. 🔄 Last Modified: April 2, 2025, 8:37 p.m.

4.3

CVSS3.1

CVE-2024-52362 - IBM App Connect Enterprise Certified Container denial of service

IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper val…

📅 Published: March 12, 2025, 2:04 p.m. 🔄 Last Modified: Sept. 1, 2025, 1:06 a.m.
Total resulsts: 343942
Page 5834 of 34,395
« previous page » next page
Filters