6.9

CVSS4.0

CVE-2025-57791 - Argument Injection Vulnerability in CommServe

An issue was discovered in Commvault before 11.36.60. A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session …

πŸ“… Published: Aug. 20, 2025, 3:22 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 3:22 a.m.

8.7

CVSS4.0

CVE-2025-57790 - Path Traversal Vulnerability

An issue was discovered in Commvault before 11.36.60. A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.

πŸ“… Published: Aug. 20, 2025, 3:22 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 3:22 a.m.

5.3

CVSS4.0

CVE-2025-57789 - Vulnerability in Initial Administrator Login Process

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

πŸ“… Published: Aug. 20, 2025, 3:22 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 3:22 a.m.

8.8

CVSS3.1

CVE-2025-8141 - Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary fil…

πŸ“… Published: Aug. 20, 2025, 1:44 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 1:44 a.m.

7.5

CVSS3.1

CVE-2025-8289 - Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserializa…

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This…

πŸ“… Published: Aug. 20, 2025, 1:44 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 1:44 a.m.

8.8

CVSS3.1

CVE-2025-8145 - Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The addition…

πŸ“… Published: Aug. 20, 2025, 1:44 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 1:44 a.m.

9.3

CVSS4.0

CVE-2024-12223 - Stored Cross-site Scripting (XSS) in Nutanix Prism Central

Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

πŸ“… Published: Aug. 20, 2025, 12:44 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:44 a.m.

0.0

CVE-2025-9132 -

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Aug. 20, 2025, 12:41 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:41 a.m.

5.1

CVSS4.0

CVE-2025-9193 - TOTVS Portal Meu RH Password Reset redirect

A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to open redirect. The attack may be performed from a remote location. The exploit has been published and m…

πŸ“… Published: Aug. 20, 2025, 12:02 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:02 a.m.

0.0

CVE-2025-55498 -

Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:38 p.m.
Total resulsts: 306757
Page 59 of 30,676
Β« previous page Β» next page
Filters