8.7

CVSS4.0

CVE-2025-24007 -

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection a…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-51447 -

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an unauthenticated remote attacke…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: Aug. 22, 2025, 8:32 p.m.

5.1

CVSS4.0

CVE-2024-51446 -

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by upl…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: Sept. 23, 2025, 3:29 p.m.

7.1

CVSS4.0

CVE-2024-51445 -

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to read arbitrary data f…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: Sept. 23, 2025, 3:34 p.m.

7.1

CVSS4.0

CVE-2024-51444 -

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorizat…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: Sept. 23, 2025, 3:38 p.m.

8.7

CVSS4.0

CVE-2024-23815 -

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zone…

📅 Published: May 13, 2025, 9:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-40628 - SQL Injection in DomainsPRO

SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.

📅 Published: May 13, 2025, 9:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-4647 - A user with elevated privileges can bypass sanitization measures by replacing the content of an exi…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG. This issue affects web: from 24.10.0 before…

📅 Published: May 13, 2025, 9:31 a.m. 🔄 Last Modified: Oct. 22, 2025, 2:13 p.m.

7.2

CVSS3.1

CVE-2025-4646 - A high privilege user is able to create and use a valid admin API token in centreon-web

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

📅 Published: May 13, 2025, 9:17 a.m. 🔄 Last Modified: Oct. 22, 2025, 2:13 p.m.

9.4

CVSS4.0

CVE-2025-22248 - [pgpool] Unauthenticated access to postgres through pgpool

The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication chec…

📅 Published: May 13, 2025, 9:13 a.m. 🔄 Last Modified: July 18, 2025, 6:58 p.m.
Total resulsts: 348208
Page 5348 of 34,821
« previous page » next page
Filters