7

CVSS4.0

CVE-2025-0417 - Valmet DNA Lack of protection against brute force attacks

Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.

📅 Published: April 1, 2025, 4:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-0418 - Valmet DNA user passwords in plain text

Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.

📅 Published: April 1, 2025, 3:59 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-1534 - Cross-site Scripting (Stored)

CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, fr…

📅 Published: April 1, 2025, 3:25 a.m. 🔄 Last Modified: Oct. 14, 2025, 5:25 p.m.

6.5

CVSS3.1

CVE-2025-3051 - Linux::Statm::Tiny for Perl allows untrusted code to be included from the current working directory

Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary co…

📅 Published: April 1, 2025, 2:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-30673 - Sub::HandlesVia for Perl allows untrusted code to be included from the current working directory

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary cod…

📅 Published: April 1, 2025, 2:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-30672 - Mite for Perl generates code with an untrusted search path vulnerability

Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code exec…

📅 Published: April 1, 2025, 1:51 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-21384 - Azure Health Bot Elevation of Privilege Vulnerability

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

📅 Published: April 1, 2025, 12:40 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS4.0

CVE-2025-3045 - oretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injection

A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /remove-apartment.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remote…

📅 Published: April 1, 2025, 12:31 a.m. 🔄 Last Modified: May 27, 2025, 6:53 p.m.

6.9

CVSS4.0

CVE-2025-3043 - GuoMinJim PersonManage login preHandle path traversal

A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the file /login/. The manipulation of the argument Request leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to t…

📅 Published: April 1, 2025, 12:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3042 - Project Worlds Online Time Table Generator updateprofile.php unrestricted upload

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the file /student/updateprofile.php. The manipulation of the argument pic leads to unrestricted upload. The attack can be initiated remotely. The exploit ha…

📅 Published: April 1, 2025, midnight 🔄 Last Modified: July 9, 2025, 3:38 p.m.
Total resulsts: 349182
Page 6088 of 34,919
« previous page » next page
Filters