8.3

CVSS3.1

CVE-2025-62514 - `libparsec_crypto` does not check for weak order point of curve 25519

Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means…

πŸ“… Published: Jan. 29, 2026, 3:46 p.m. πŸ”„ Last Modified: March 2, 2026, 6:34 p.m.

5.3

CVSS4.0

CVE-2026-1596 - D-Link DWR-M961 formLtefotaUpgradeQuectel sub_419920 command injection

A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published a…

πŸ“… Published: Jan. 29, 2026, 3:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:05 a.m.

6.9

CVSS4.0

CVE-2026-1595 - itsourcecode Society Management System edit_student_query.php sql injection

A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

πŸ“… Published: Jan. 29, 2026, 3:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:05 a.m.

5.1

CVSS4.0

CVE-2026-0936 - Insertion of Sensitive Information into Logfile

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disable…

πŸ“… Published: Jan. 29, 2026, 3:30 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:42 a.m.

7

CVSS4.0

CVE-2025-13905 -

CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.

πŸ“… Published: Jan. 29, 2026, 3:20 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:42 a.m.

7.5

CVSS3.1

CVE-2025-7714 - Time Based SQLi in Global Medya's PHP CMS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows Command Line Execution through SQL Injection.This issue affects Content Management System (CMS): through 2107202…

πŸ“… Published: Jan. 29, 2026, 2:44 p.m. πŸ”„ Last Modified: March 10, 2026, 5:56 p.m.

7.5

CVSS3.1

CVE-2025-7713 - Reflected XSS in Global Medya's PHP CMS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows XSS Through HTTP Headers.This issue affects Content Management System (CMS): through 21072025.

πŸ“… Published: Jan. 29, 2026, 2:38 p.m. πŸ”„ Last Modified: March 10, 2026, 5:55 p.m.

6.9

CVSS4.0

CVE-2026-1594 - itsourcecode Society Management System add_expenses.php sql injection

A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of the argument detail leads to sql injection. Remote exploitation of the attack is possible. The expl…

πŸ“… Published: Jan. 29, 2026, 2:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:05 a.m.

6.9

CVSS4.0

CVE-2026-1593 - itsourcecode Society Management System edit_expenses_query.php sql injection

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_expenses_query.php. Executing a manipulation of the argument detail can lead to sql injection. The attack may be launched remotely. The ex…

πŸ“… Published: Jan. 29, 2026, 2:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:04 a.m.

8.5

CVSS4.0

CVE-2020-37021 - Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.
Total resulsts: 344257
Page 1402 of 34,426
Β« previous page Β» next page
Filters