8.7

CVSS3.1

CVE-2025-0064 - Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Co…

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality…

πŸ“… Published: Feb. 11, 2025, 12:33 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 6:41 p.m.

5.4

CVSS3.1

CVE-2025-0054 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser…

πŸ“… Published: Feb. 11, 2025, 12:32 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-1165 - Lumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been di…

πŸ“… Published: Feb. 11, 2025, 12:31 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2025-1164 - code-projects Police FIR Record Management System Add Record stack-based overflow

A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach …

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: April 11, 2025, 6:33 p.m.

6.5

CVSS3.1

CVE-2022-37660 - hostapd: Public Key Exchange (PKEX) Reuse Vulnerability in hostapd

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encr…

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:15 p.m.

3.8

CVSS3.1

CVE-2024-51324 -

An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 10:15 p.m.

5.1

CVSS3.1

CVE-2022-35202 -

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystor…

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

7.9

CVSS3.1

CVE-2024-33469 -

An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Feb. 13, 2025, 3:15 p.m.

6.8

CVSS3.1

CVE-2024-54916 -

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-54772 -

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with …

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: June 30, 2025, 2:48 p.m.
Total resulsts: 343194
Page 6204 of 34,320
Β« previous page Β» next page
Filters