8.7

CVSS4.0

CVE-2025-4008 - Arbitrary Command Injection in Smartbedded MeteoBridge

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote una…

📅 Published: May 21, 2025, 3:31 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2024-23337 - jq has signed integer overflow in jv.c:jvp_array_write

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.

📅 Published: May 21, 2025, 2:34 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

5.3

CVSS4.0

CVE-2025-5029 - Kingdee Cloud Galaxy Private Cloud BBC System File deleteFileAction.jhtml path traversal

A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the compone…

📅 Published: May 21, 2025, 2:31 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

2.4

CVSS4.0

CVE-2025-1421 - Formula injection in a CSV file in Proget MDM

Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC. …

📅 Published: May 21, 2025, 1:04 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

2.4

CVSS4.0

CVE-2025-1420 - XSS in Proget MDM

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

📅 Published: May 21, 2025, 1:04 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

2.4

CVSS4.0

CVE-2025-1419 - XSS in Proget MDM

Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

📅 Published: May 21, 2025, 1:03 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

5.1

CVSS4.0

CVE-2025-1418 - Information disclosure in Proget MDM

A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices).    This issue has been fixed i…

📅 Published: May 21, 2025, 1:03 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

4.6

CVSS4.0

CVE-2025-1417 - Information disclosure in Proget MDM

In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This information include user ids, email addresses, first names, last names and device UUIDs. The last one can be used for exploitation of CVE…

📅 Published: May 21, 2025, 1:03 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

7

CVSS4.0

CVE-2025-1416 - Password disclosure in Proget MDM

In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of targetted devices, which might be obtained by exploiting CVE-2025-1415 or CVE-2025-141…

📅 Published: May 21, 2025, 1:03 p.m. 🔄 Last Modified: May 21, 2025, 8:24 p.m.

6.5

CVSS3.1

CVE-2025-48417 - Hard-Coded Certificate and Private Key for HTTPS Web Interface in eCharge Hardy Barth cPH2 / cPP2 c…

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin in…

📅 Published: May 21, 2025, 12:30 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:19 p.m.
Total resulsts: 343910
Page 4773 of 34,391
« previous page » next page
Filters