3.5

CVSS3.1

CVE-2025-30235 -

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of failed authentication attempts, because concurrent attempts are mishandled.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-29401 -

An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 6:49 p.m.

9.8

CVSS3.1

CVE-2024-57061 -

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-55009 -

A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: March 24, 2025, 5:45 p.m.

6.3

CVSS3.1

CVE-2025-29405 -

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 7:35 p.m.

6.5

CVSS3.1

CVE-2025-26816 -

A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-29137 -

Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 8:37 p.m.

3.5

CVSS3.1

CVE-2025-30259 -

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with โ€ฆ

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2025-30258 - gnupg: verification DoS due to a malicious subkey in the keyring

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 16, 2025, 4:53 p.m.

8.3

CVSS3.1

CVE-2024-55551 -

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

๐Ÿ“… Published: March 19, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 26, 2025, 4:33 p.m.
Total resulsts: 347769
Page 6167 of 34,777
ยซ previous page ยป next page
Filters