9.1

CVSS3.1

CVE-2025-24977 - OpenCTI has remote code execution and sensitive secrets exposed through web hook

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the ma…

πŸ“… Published: May 5, 2025, 5:07 p.m. πŸ”„ Last Modified: May 22, 2025, 3:52 p.m.

1.1

CVSS4.0

CVE-2024-51991 - October CMS Allows Unprotected SVG Rename in Media Manager

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vuln…

πŸ“… Published: May 5, 2025, 5:04 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 6:54 p.m.

7.3

CVSS4.0

CVE-2025-0217 - Privileged Remote Access Authentication Bypass

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.

πŸ“… Published: May 5, 2025, 5 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2025-1992 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

πŸ“… Published: May 5, 2025, 4:54 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2024-11615 - Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions. This is due to the plugin not properly validating a file or its path prior to deleting it. This makes …

πŸ“… Published: May 5, 2025, 4:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-4281 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclo…

A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack r…

πŸ“… Published: May 5, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-4316 -

Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through 2025.1.6.0, and all versions…

πŸ“… Published: May 5, 2025, 2 p.m. πŸ”„ Last Modified: June 17, 2025, 2:13 p.m.

2.3

CVSS4.0

CVE-2025-2545 - Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could comp…

πŸ“… Published: May 5, 2025, 11:28 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-4272 - Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation lea…

πŸ“… Published: May 5, 2025, 11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-2905 - An XML External Entity (XXE) vulnerability in Multiple WSO2 Products

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read sensitive files from …

πŸ“… Published: May 5, 2025, 9:02 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 12:15 p.m.
Total resulsts: 346573
Page 5291 of 34,658
Β« previous page Β» next page
Filters