7.8

CVSS3.1

CVE-2025-20645 -

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.

πŸ“… Published: March 3, 2025, 2:25 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2025-20644 -

In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…

πŸ“… Published: March 3, 2025, 2:25 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:16 p.m.

5.3

CVSS4.0

CVE-2025-1845 - ESAFENET DSM examExportPDF command injection

A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the function examExportPDF of the file /admin/plan/examExportPDF. The manipulation of the argument s leads to command injection. The attack can be launched remotely. The exploit has be…

πŸ“… Published: March 3, 2025, 2 a.m. πŸ”„ Last Modified: May 28, 2025, 5:13 p.m.

5.3

CVSS4.0

CVE-2025-1844 - ESAFENET CDG backupLogDetail.jsp sql injection

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. Affected is an unknown function of the file /CDGServer3/logManagement/backupLogDetail.jsp. The manipulation of the argument logTaskId leads to sql injection. It is possible to launch the attack remo…

πŸ“… Published: March 3, 2025, 1:31 a.m. πŸ”„ Last Modified: May 28, 2025, 5:10 p.m.

5.3

CVSS4.0

CVE-2025-1843 - Mini-Tmall ProductMapper.java select sql injection

A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.java. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit …

πŸ“… Published: March 3, 2025, 1 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 9:29 p.m.

5.3

CVSS4.0

CVE-2025-1842 - FITSTATS Technologies AthleteMonitoring login.php cross site scripting

A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit h…

πŸ“… Published: March 3, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1841 - ESAFENET CDG ClientSortLog.jsp sql injection

A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the argument startDate/endDate leads to sql injection. It is possible to initiate the attack remotely. The e…

πŸ“… Published: March 3, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:05 p.m.

6.9

CVSS3.1

CVE-2025-27370 -

OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick a Client into writing attacker-controlled values into the audience, including token endpoints or issu…

πŸ“… Published: March 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-25967 -

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections al…

πŸ“… Published: March 3, 2025, midnight πŸ”„ Last Modified: March 6, 2025, 12:21 p.m.

6.5

CVSS3.1

CVE-2025-25953 -

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.

πŸ“… Published: March 3, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 4:15 p.m.
Total resulsts: 349182
Page 6500 of 34,919
Β« previous page Β» next page
Filters