9.8

CVSS3.1

CVE-2025-28035 -

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:14 p.m.

7.3

CVSS3.1

CVE-2025-29621 -

Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

7.8

CVSS3.1

CVE-2025-43950 -

DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, th…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-43951 -

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:15 p.m.

6.1

CVSS3.1

CVE-2025-43952 -

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

6.1

CVSS3.1

CVE-2023-43378 -

A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-3849 - YXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password change

A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has be…

πŸ“… Published: April 21, 2025, 11:31 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

3.8

CVSS3.1

CVE-2025-2987 - IBM Maximo Asset Management server-side request forgery

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: April 21, 2025, 11:24 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

6.9

CVSS4.0

CVE-2025-3847 - markparticle WebServer Login httprequest.cpp sql injection

A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remo…

πŸ“… Published: April 21, 2025, 11 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

6.9

CVSS4.0

CVE-2025-3846 - markparticle WebServer Registration httprequest.cpp sql injection

A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file code/http/httprequest.cpp of the component Registration. The manipulation of the argument username/password leads to sql injection. The atta…

πŸ“… Published: April 21, 2025, 10:31 p.m. πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.
Total resulsts: 291884
Page 85 of 29,189
Β« previous page Β» next page
Filters