8.3

CVSS3.1

CVE-2025-41407 - SQL Injection

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.

📅 Published: May 23, 2025, 10:29 a.m. 🔄 Last Modified: June 16, 2025, 3:15 p.m.

8.3

CVSS3.1

CVE-2025-36527 - SQL Injection

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.

📅 Published: May 23, 2025, 10:28 a.m. 🔄 Last Modified: June 16, 2025, 3:15 p.m.

9.1

CVSS4.0

CVE-2025-3895 - Low token entropy in MegaBIP

Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administ…

📅 Published: May 23, 2025, 10:20 a.m. 🔄 Last Modified: June 23, 2025, 7:31 p.m.

4.8

CVSS4.0

CVE-2025-3894 - Stored XSS in MegaBIP

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

📅 Published: May 23, 2025, 10:20 a.m. 🔄 Last Modified: June 23, 2025, 7:31 p.m.

8.6

CVSS4.0

CVE-2025-3893 - SQL Injection in MegaBIP

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

📅 Published: May 23, 2025, 10:20 a.m. 🔄 Last Modified: June 23, 2025, 7:31 p.m.

5.1

CVSS4.0

CVE-2025-4379 - Reflected XSS in DobryCMS

DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in szukaj parameter allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened. A hotfix for affected versions was released on 29.04.2025. It…

📅 Published: May 23, 2025, 10 a.m. 🔄 Last Modified: May 23, 2025, 3:54 p.m.

8.4

CVSS4.0

CVE-2024-13945 - Stored Absolute Path Traversal

Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

📅 Published: May 23, 2025, 9:18 a.m. 🔄 Last Modified: July 12, 2025, 10:10 p.m.

6.9

CVSS4.0

CVE-2025-47149 -

The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pattern file, information in the server where the product is ru…

📅 Published: May 23, 2025, 9:09 a.m. 🔄 Last Modified: May 23, 2025, 3:54 p.m.

6.4

CVSS3.1

CVE-2025-5096 - TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multip…

The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data-attributes in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This…

📅 Published: May 23, 2025, 8:23 a.m. 🔄 Last Modified: July 11, 2025, 7:41 p.m.

0.0

CVE-2025-5104 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: May 23, 2025, 5:02 a.m. 🔄 Last Modified: July 5, 2025, 11:15 p.m.
Total resulsts: 343054
Page 4665 of 34,306
« previous page » next page
Filters