8.8

CVSS3.1

CVE-2025-3616 - Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level acc…

📅 Published: April 22, 2025, 4:21 a.m. 🔄 Last Modified: May 28, 2025, 5:38 p.m.

7.1

CVSS3.1

CVE-2024-46899 - Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitac…

Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 1…

📅 Published: April 22, 2025, 4:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-2300 - Information exposure vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center …

Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.

📅 Published: April 22, 2025, 4:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-3577 -

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affect…

📅 Published: April 22, 2025, 2:18 a.m. 🔄 Last Modified: June 23, 2025, 7:29 p.m.

6.7

CVSS3.1

CVE-2025-1732 -

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable devi…

📅 Published: April 22, 2025, 1:57 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

7.8

CVSS3.1

CVE-2025-1731 -

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malic…

📅 Published: April 22, 2025, 1:52 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

5.3

CVSS4.0

CVE-2025-3856 - xxyopen Novel-Plus searchByPage sql injection

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

📅 Published: April 22, 2025, 1 a.m. 🔄 Last Modified: Oct. 15, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2025-3855 - CodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of the argument profile_…

📅 Published: April 22, 2025, 12:31 a.m. 🔄 Last Modified: Aug. 1, 2025, 10:06 p.m.

8.6

CVSS4.0

CVE-2025-3854 - H3C GR-3000AX HTTP POST Request aspForm Edit_List_SSID buffer overflow

A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argume…

📅 Published: April 22, 2025, 12:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-3850 - YXJ2018 SpringBoot-Vue-OnlineExam API improper authentication

A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated remotely. The complexity of an attack is rat…

📅 Published: April 22, 2025, midnight 🔄 Last Modified: Oct. 15, 2025, 6:52 p.m.
Total resulsts: 348632
Page 5646 of 34,864
« previous page » next page
Filters