8.8

CVSS3.1

CVE-2025-0975 - IBM MQ code execution

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

πŸ“… Published: Feb. 28, 2025, 2:20 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

8.8

CVSS3.1

CVE-2025-26326 -

A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept any password entere…

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2025-26263 -

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-10306 - Mod_proxy_cluster: mod_proxy_cluster unauthorized mcmp requests

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests…

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-25461 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this category, the payload is stored on the server an…

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:32 p.m.

9.1

CVSS3.1

CVE-2024-12225 - Io.quarkus:quarkus-security-webauthn: quarkus webauthn unexpected authentication bypass

A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endp…

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 7:12 a.m.

4.8

CVSS3.1

CVE-2025-25430 -

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:06 p.m.

4.8

CVSS3.1

CVE-2025-25429 -

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:07 p.m.

8

CVSS3.1

CVE-2025-25428 -

TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:07 p.m.

8

CVSS3.1

CVE-2025-25635 -

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.

πŸ“… Published: Feb. 28, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 1:40 a.m.
Total resulsts: 349182
Page 6518 of 34,919
Β« previous page Β» next page
Filters