10

CVSS4.0

CVE-2025-69425 - Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who ext…

📅 Published: Jan. 9, 2026, 4:14 p.m. 🔄 Last Modified: April 15, 2026, 2:34 p.m.

2.3

CVSS3.1

CVE-2025-46643 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overf…

📅 Published: Jan. 9, 2026, 4:07 p.m. 🔄 Last Modified: Feb. 5, 2026, 1:26 p.m.

5.3

CVSS4.0

CVE-2025-15492 - RainyGao DocSys GroupMemberMapper.xml sql injection

A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a manipulation of the argument searchWord results in sql injection. It is possible to initiate the attack remotely. The …

📅 Published: Jan. 9, 2026, 4:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:25 a.m.

5.3

CVSS3.1

CVE-2026-0817 - CampaignEvents API missing authorization exposes meeting and chat URLs

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39.

📅 Published: Jan. 9, 2026, 3:50 p.m. 🔄 Last Modified: April 18, 2026, 4:45 p.m.

2.7

CVSS3.1

CVE-2025-46676 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive …

📅 Published: Jan. 9, 2026, 3:48 p.m. 🔄 Last Modified: Feb. 5, 2026, 1:28 p.m.

5.3

CVSS4.0

CVE-2026-0803 - PHPGurukul Online Course Registration System enroll.php sql injection

A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in sql injection. The attack may be launched remotely. The exp…

📅 Published: Jan. 9, 2026, 3:32 p.m. 🔄 Last Modified: April 18, 2026, 7:30 a.m.

6

CVSS3.1

CVE-2025-46644 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization…

📅 Published: Jan. 9, 2026, 3:31 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

9.8

CVSS3.1

CVE-2025-14598 - CVE-2025-14598

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

📅 Published: Jan. 9, 2026, 12:14 p.m. 🔄 Last Modified: Feb. 10, 2026, 8:29 p.m.

8.6

CVSS4.0

CVE-2025-66052 - Command injection in Vivotek IP7137 cameras

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access …

📅 Published: Jan. 9, 2026, 11:54 a.m. 🔄 Last Modified: Jan. 14, 2026, 5:50 p.m.

6.9

CVSS4.0

CVE-2025-66051 - Path traversal in Vivotek IP7137 cameras

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has …

📅 Published: Jan. 9, 2026, 11:54 a.m. 🔄 Last Modified: Jan. 14, 2026, 5:49 p.m.
Total resulsts: 346514
Page 1943 of 34,652
« previous page » next page
Filters