8.7

CVSS3.1

CVE-2025-0595 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEX…

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

📅 Published: March 17, 2025, 1:47 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2024-9055 - DPA Countermeasures need reseeding

The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.

📅 Published: March 17, 2025, 1:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS3.1

CVE-2019-6697 -

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripti…

📅 Published: March 17, 2025, 1:40 p.m. 🔄 Last Modified: July 24, 2025, 8:15 p.m.

4.7

CVSS3.1

CVE-2020-9295 -

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files…

📅 Published: March 17, 2025, 1:40 p.m. 🔄 Last Modified: Aug. 14, 2025, 9:11 p.m.

6.9

CVSS4.0

CVE-2025-2379 - PHPGurukul Apartment Visitors Management System create-pass.php sql injection

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploi…

📅 Published: March 17, 2025, 1:31 p.m. 🔄 Last Modified: May 6, 2025, 5:26 p.m.

6.5

CVSS3.1

CVE-2025-29788 - Sylius PayPal Plugin Payment Amount Manipulation Vulnerability

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user modifies the item quantity in their shopping cart after initiat…

📅 Published: March 17, 2025, 1:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-29787 - zip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary F…

`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used for later files in t…

📅 Published: March 17, 2025, 1:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-29786 - Memory Exhaustion in Expr Parser with Unrestricted Input

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract Syntax Tree (AST) node for each part of the expression. In scenarios wher…

📅 Published: March 17, 2025, 1:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS4.0

CVE-2025-27102 - Agate vulnerable to HTML injection in user signup - Administrator phishing risk

Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the email sent to administrative users. The Agate …

📅 Published: March 17, 2025, 1:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2020-29010 -

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitiv…

📅 Published: March 17, 2025, 1:06 p.m. 🔄 Last Modified: July 24, 2025, 8:15 p.m.
Total resulsts: 347732
Page 6178 of 34,774
« previous page » next page
Filters