6.9

CVSS4.0

CVE-2025-24980 - Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.…

📅 Published: Feb. 7, 2025, 7:56 p.m. 🔄 Last Modified: Jan. 16, 2026, 6:16 p.m.

5.3

CVSS4.0

CVE-2021-41528 - Improper authorization related to Import / Export interfaces on RISC Platform

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

📅 Published: Feb. 7, 2025, 7:54 p.m. 🔄 Last Modified: Feb. 7, 2025, 9:18 p.m.

2.3

CVSS4.0

CVE-2021-41527 - 2FA bypass on the RISC Platform

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

📅 Published: Feb. 7, 2025, 7:44 p.m. 🔄 Last Modified: March 13, 2025, 2:15 p.m.

5.3

CVSS4.0

CVE-2025-1106 - CmsEasy database_admin.php restore_action path traversal

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed t…

📅 Published: Feb. 7, 2025, 6:31 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

5.3

CVSS4.0

CVE-2025-1105 - SiberianCMS HTTP GET Request flat cross site scripting

A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. The attack may be launched remo…

📅 Published: Feb. 7, 2025, 6 p.m. 🔄 Last Modified: Nov. 4, 2025, 7:47 p.m.

7.7

CVSS3.1

CVE-2022-26389 - Improper Access Control Vulnerability in ELI Electrocardiograph Devices

An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior;  * ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior;  * ELI 250c/BUR 250c Resting Electrocardiograph:…

📅 Published: Feb. 7, 2025, 5:07 p.m. 🔄 Last Modified: Feb. 7, 2025, 6:49 p.m.

6.4

CVSS3.1

CVE-2022-26388 - Use of Hard-Coded Password Vulnerability in ELI Electrocardiograph Devices

A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 …

📅 Published: Feb. 7, 2025, 5:06 p.m. 🔄 Last Modified: Feb. 7, 2025, 6:50 p.m.

6.9

CVSS4.0

CVE-2025-1104 - D-Link DHP-W310AV authentication spoofing

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

📅 Published: Feb. 7, 2025, 4:31 p.m. 🔄 Last Modified: May 21, 2025, 4:13 p.m.

6.8

CVSS3.1

CVE-2024-7425 - WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manag…

📅 Published: Feb. 7, 2025, 4:21 p.m. 🔄 Last Modified: Feb. 11, 2025, 7:12 p.m.

4.3

CVSS3.1

CVE-2024-9661 - WP All Import Pro <= 4.9.7 - Cross-Site Request Forgery to Imported Content Deletion

The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.7. This is due to missing nonce validation on the delete_and_edit function. This makes it possible for unauthenticated attackers to delete imported content (posts, commen…

📅 Published: Feb. 7, 2025, 3:21 p.m. 🔄 Last Modified: Feb. 18, 2025, 7:15 p.m.
Total resulsts: 343040
Page 6200 of 34,304
« previous page » next page
Filters