7

CVSS3.1

CVE-2025-28128 -

An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 12, 2025, 7:29 p.m.

6.4

CVSS3.1

CVE-2025-46595 -

An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided…

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-25775 -

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 7:08 p.m.

7.5

CVSS3.1

CVE-2025-32983 -

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 4:57 p.m.

6.8

CVSS3.1

CVE-2025-46599 -

CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credent…

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46547 -

In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-46613 - From CVEorg collector

OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-32985 -

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-28354 -

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request.

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-46546 -

In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processV…

πŸ“… Published: April 25, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:42 p.m.
Total resulsts: 349182
Page 5666 of 34,919
Β« previous page Β» next page
Filters