7.5

CVSS3.1

CVE-2025-24366 - Insufficient sanitization of user provided rsync command in SFTPGo

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default commands some optional commands can be activated, one of them being `rsync`. It is disabled in the default configuration and it is limited to the lโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 9:16 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-24980 - Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.โ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 6:16 p.m.

5.3

CVSS4.0

CVE-2021-41528 - Improper authorization related to Import / Export interfaces on RISC Platform

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited toย access the import / export functionality with low privileges.

๐Ÿ“… Published: Feb. 7, 2025, 7:54 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2021-41527 - 2FA bypass on the RISC Platform

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to theย saas-2021-12-29 releaseย can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasnโ€™t been completed.

๐Ÿ“… Published: Feb. 7, 2025, 7:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1106 - CmsEasy database_admin.php restore_action path traversal

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed tโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: July 13, 2025, 11:07 a.m.

5.3

CVSS4.0

CVE-2025-1105 - SiberianCMS HTTP GET Request flat cross site scripting

A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. The attack may be launched remoโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 6 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 7:47 p.m.

7.7

CVSS3.1

CVE-2022-26389 - Improper Access Control Vulnerability in ELI Electrocardiograph Devices

An improper access control vulnerability may allow privilege escalation.This issue affects:ย  * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior;ย  * ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior;ย  * ELI 250c/BUR 250c Resting Electrocardiograph:โ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 5:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2022-26388 - Use of Hard-Coded Password Vulnerability in ELI Electrocardiograph Devices

A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 โ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 5:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1104 - D-Link DHP-W310AV authentication spoofing

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Feb. 7, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: May 21, 2025, 4:13 p.m.

6.8

CVSS3.1

CVE-2024-7425 - WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Managโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 4:21 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:21 p.m.
Total resulsts: 348552
Page 6751 of 34,856
ยซ previous page ยป next page
Filters