2.3

CVSS4.0

CVE-2025-1795 - Mishandling of comma during folding and unicode-encoding of email headers

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted b…

πŸ“… Published: Feb. 28, 2025, 6:59 p.m. πŸ”„ Last Modified: April 22, 2026, 1:30 p.m.

4.8

CVSS3.1

CVE-2025-27408 - Manifest Uses a One-Way Hash without a Salt

Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. This exposes user passwords to a higher risk of being cracked if an attacker gains access to the database. Without the use of a salt, ident…

πŸ“… Published: Feb. 28, 2025, 5:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-24316 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sens…

The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.

πŸ“… Published: Feb. 28, 2025, 5:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-24318 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Sensitive Cookie…

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

πŸ“… Published: Feb. 28, 2025, 5:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-20049 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Cross-site Scrip…

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

πŸ“… Published: Feb. 28, 2025, 5:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-24849 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Cleartext Transm…

Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.

πŸ“… Published: Feb. 28, 2025, 4:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-24843 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Storage of Sensi…

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

πŸ“… Published: Feb. 28, 2025, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-23405 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Improper Output …

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

πŸ“… Published: Feb. 28, 2025, 4:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-20060 - Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Priv…

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

πŸ“… Published: Feb. 28, 2025, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-0985 - IBM MQ information disclosure

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local user.

πŸ“… Published: Feb. 28, 2025, 4:21 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:26 p.m.
Total resulsts: 349182
Page 6512 of 34,919
Β« previous page Β» next page
Filters