6.4

CVSS3.1

CVE-2025-46544 -

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 6:34 p.m.

6.5

CVSS3.1

CVE-2025-32979 -

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 4:58 p.m.

2.4

CVSS3.1

CVE-2024-57375 -

Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-28128 -

An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 12, 2025, 7:29 p.m.

6.4

CVSS3.1

CVE-2025-46595 -

An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided…

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-25775 -

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 7:08 p.m.

7.5

CVSS3.1

CVE-2025-32983 -

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 4:57 p.m.

6.8

CVSS3.1

CVE-2025-46599 -

CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credent…

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46547 -

In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-46613 - From CVEorg collector

OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346575
Page 5405 of 34,658
Β« previous page Β» next page
Filters