4.9

CVSS3.1

CVE-2025-3430 - 3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'printer_text'

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u…

πŸ“… Published: April 8, 2025, 7:01 a.m. πŸ”„ Last Modified: April 8, 2026, 5 p.m.

4.9

CVSS3.1

CVE-2025-3429 - 3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'material_text'

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for …

πŸ“… Published: April 8, 2025, 7:01 a.m. πŸ”„ Last Modified: April 8, 2026, 4:47 p.m.

4.9

CVSS3.1

CVE-2025-3427 - 3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'infill_text'

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for un…

πŸ“… Published: April 8, 2025, 7:01 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

5.3

CVSS4.0

CVE-2025-3413 - opplus springboot-admin SysGeneratorController.java code deserialization

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization. The att…

πŸ“… Published: April 8, 2025, 6 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:09 p.m.

4.3

CVSS3.1

CVE-2025-0361 -

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

πŸ“… Published: April 8, 2025, 5:38 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 2:41 p.m.

4.3

CVSS3.1

CVE-2024-47261 -

51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

πŸ“… Published: April 8, 2025, 5:33 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 2:46 p.m.

5.3

CVSS4.0

CVE-2025-3412 - mymagicpower AIAS InferController.java server-side request forgery

A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_platform/train-platform/src/main/java/top/aias/training/controller/InferController.java. The manipulation of the argument url leads to server-side reque…

πŸ“… Published: April 8, 2025, 5:31 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:40 p.m.

5.3

CVSS4.0

CVE-2025-3411 - mymagicpower AIAS AsrController.java server-side request forgery

A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. The manipulation of the argument url leads to server-sid…

πŸ“… Published: April 8, 2025, 5 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:40 p.m.

5.3

CVSS4.0

CVE-2025-3410 - mymagicpower AIAS LocalStorageController.java unrestricted upload

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument File leads to unrestricted up…

πŸ“… Published: April 8, 2025, 5 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:40 p.m.

8.8

CVSS3.1

CVE-2025-20946 -

Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to pair with specific bluetooth devices without user interaction.

πŸ“… Published: April 8, 2025, 4:50 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 344072
Page 5464 of 34,408
Β« previous page Β» next page
Filters