6.9

CVSS4.0

CVE-2025-1555 - hzmanyun Education and Training System saveImage unrestricted upload

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public…

πŸ“… Published: Feb. 21, 2025, 9 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 2:12 a.m.

5.1

CVSS4.0

CVE-2025-1548 - iteachyou Dreamer CMS edit cross site scripting

A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting. The attack can be initiated remotely. T…

πŸ“… Published: Feb. 21, 2025, 5 p.m. πŸ”„ Last Modified: April 4, 2025, 4:40 p.m.

8.6

CVSS3.1

CVE-2025-1403 - Qiskit SDK denial of service

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

πŸ“… Published: Feb. 21, 2025, 4:55 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:25 p.m.

5.5

CVSS3.1

CVE-2024-45673 - IBM Security Verify Bridge information disclosure

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.

πŸ“… Published: Feb. 21, 2025, 4:45 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 10:15 p.m.

6.9

CVSS4.0

CVE-2025-1546 - BDCOM Behavior Management and Auditing System operate.mds log_operate_clear os command injection

A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command inj…

πŸ“… Published: Feb. 21, 2025, 4:31 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 2:33 p.m.

5.3

CVSS4.0

CVE-2025-1544 - dingfanzu CMS loadShopInfo.php sql injection

A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. Affected is an unknown function of the file /ajax/loadShopInfo.php. The manipulation of the argument shopId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclo…

πŸ“… Published: Feb. 21, 2025, 4 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-1543 - iteachyou Dreamer CMS ueditor-1.4.3.3 path traversal

A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3. This issue affects some unknown processing of the file /resource/js/ueditor-1.4.3.3. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to…

πŸ“… Published: Feb. 21, 2025, 4 p.m. πŸ”„ Last Modified: April 4, 2025, 4:36 p.m.

8.7

CVSS4.0

CVE-2025-1539 - D-Link DAP-1320 storagein.pd-XXXXXX replace_special_char stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. Affected by this issue is the function replace_special_char of the file /storagein.pd-XXXXXX. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been d…

πŸ“… Published: Feb. 21, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:42 p.m.

8.7

CVSS4.0

CVE-2025-1538 - D-Link DAP-1320 api set_ws_action heap-based overflow

A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: Feb. 21, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 8:54 p.m.

5.3

CVSS4.0

CVE-2025-1537 - Harpia DiagSystem atualatendimento_jpeg.php sql injection

A vulnerability was found in Harpia DiagSystem 12. It has been rated as critical. This issue affects some unknown processing of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument codexame leads to sql injection. The attack may be initiated remotely. The exploit ha…

πŸ“… Published: Feb. 21, 2025, 2:31 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:15 p.m.
Total resulsts: 344064
Page 6151 of 34,407
Β« previous page Β» next page
Filters