6.1

CVSS3.1

CVE-2025-46611 -

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 1:02 a.m.

9.8

CVSS3.1

CVE-2025-26846 -

An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 1:51 p.m.

8.8

CVSS3.1

CVE-2025-46610 -

ARTEC EMA Mail 6.92 allows CSRF.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: July 16, 2025, 4:49 p.m.

9.1

CVSS3.1

CVE-2024-56524 -

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 7:51 p.m.

9.8

CVSS3.1

CVE-2025-45779 -

Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 1:40 p.m.

9.8

CVSS3.1

CVE-2025-44022 -

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

πŸ“… Published: May 12, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-4552 - ContiNew Admin password unverified password change

A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. The attack can be launched remotely. The exploit …

πŸ“… Published: May 11, 2025, 11:31 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 3 p.m.

5.1

CVSS4.0

CVE-2025-4551 - ContiNew Admin file cross site scripting

A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The manipulation of the argument File leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been di…

πŸ“… Published: May 11, 2025, 11 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 3:09 p.m.

6.9

CVSS4.0

CVE-2025-4550 - PHPGurukul Apartment Visitors Management System pass-details.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the file /admin/pass-details.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely…

πŸ“… Published: May 11, 2025, 10:31 p.m. πŸ”„ Last Modified: May 16, 2025, 5:13 p.m.

6.9

CVSS4.0

CVE-2025-4549 - Campcodes Online Food Ordering System register-router.php sql injection

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/register-router.php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been d…

πŸ“… Published: May 11, 2025, 10 p.m. πŸ”„ Last Modified: May 13, 2025, 6:55 p.m.
Total resulsts: 347814
Page 5328 of 34,782
Β« previous page Β» next page
Filters