3.5

CVSS3.1

CVE-2023-35816 -

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: June 5, 2025, 2:30 p.m.

5

CVSS3.1

CVE-2023-35817 -

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: June 5, 2025, 2:30 p.m.

3.3

CVSS3.1

CVE-2025-46614 -

In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2015-2079 -

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 6:59 p.m.

4.3

CVSS3.1

CVE-2025-4035 - Libsoup: cookie domain validation bypass via uppercase characters in libsoup

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set coo…

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2025-25776 -

Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 6:58 p.m.

9.8

CVSS3.1

CVE-2025-45949 -

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leadin…

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 6:03 p.m.

4.9

CVSS3.1

CVE-2023-42404 -

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: May 12, 2025, 7:36 p.m.

10

CVSS3.1

CVE-2025-46661 -

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supplier.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: May 12, 2025, 7:30 p.m.

4.9

CVSS3.1

CVE-2024-32499 -

Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 3:06 p.m.
Total resulsts: 349182
Page 5650 of 34,919
Β« previous page Β» next page
Filters