8.8
CVE-2024-57778 -
An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.
8.6
CVE-2025-26819 -
Monero through 0.18.3.4 before ec74ff4 does not have response limits on HTTP server connections.
7.5
CVE-2025-25997 -
Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.
6.1
CVE-2025-25990 -
Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
5.1
CVE-2025-25993 -
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
4.3
CVE-2024-57969 -
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
6.5
CVE-2024-57725 -
An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.
4.8
CVE-2025-25988 -
Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.
7.5
CVE-2025-25994 -
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.
6.9
CVE-2025-26789 -
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint deployment.