6.9

CVSS4.0

CVE-2025-1695 - NGINX Unit Java Vulnerability

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). Β The…

πŸ“… Published: March 4, 2025, 12:54 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 1:59 p.m.

5.3

CVSS4.0

CVE-2025-1893 - Open5GS AMF gmm-sm.c gmm_state_authentication denial of service

A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vu…

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: March 6, 2025, 12:21 p.m.

4.8

CVSS4.0

CVE-2025-1892 - shishuocms Directory Deletion Page add.json cross site scripting

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName leads to cross site scripting. It is possible to launch the a…

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: March 5, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2021-41719 -

Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the bro…

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-48248 -

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:11 p.m.

4.3

CVSS3.1

CVE-2025-26849 -

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive information such as firewall rules.

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:27 p.m.

9.8

CVSS3.1

CVE-2024-50706 -

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:26 p.m.

6.5

CVSS3.1

CVE-2025-26320 -

t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:27 p.m.

10

CVSS3.1

CVE-2024-50707 -

Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:27 p.m.

4.3

CVSS3.1

CVE-2025-26202 -

Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an admin…

πŸ“… Published: March 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346554
Page 6205 of 34,656
Β« previous page Β» next page
Filters