7.2

CVSS3.1

CVE-2025-45752 -

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 3:49 p.m.

7.2

CVSS3.1

CVE-2025-44040 -

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed by the Supplier becaโ€ฆ

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 13, 2025, 8:15 p.m.

7.7

CVSS3.1

CVE-2024-56429 -

itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

6.8

CVSS3.1

CVE-2025-48204 -

The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

7.2

CVSS3.1

CVE-2025-45753 -

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: June 10, 2025, 7:34 p.m.

6.1

CVSS3.1

CVE-2024-57529 -

Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 3:38 p.m.

8.6

CVSS3.1

CVE-2025-48207 -

The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

8.6

CVSS3.1

CVE-2025-48205 -

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.3

CVSS3.1

CVE-2025-48202 -

The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

5.4

CVSS3.1

CVE-2025-45754 -

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

๐Ÿ“… Published: May 21, 2025, midnight ๐Ÿ”„ Last Modified: June 25, 2025, 1:50 p.m.
Total resulsts: 343883
Page 4775 of 34,389
ยซ previous page ยป next page
Filters