4.3

CVSS3.1

CVE-2025-25195 - Zulip events can leak private channel names

Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received traffic for 180 days. However, upon doing so, an event was sent to all users in the organization, not just users in…

πŸ“… Published: Feb. 13, 2025, 9:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-20615 - Qardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthori…

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based…

πŸ“… Published: Feb. 13, 2025, 9:47 p.m. πŸ”„ Last Modified: March 24, 2025, 1:39 p.m.

9.3

CVSS4.0

CVE-2025-25067 - mySCADA myPRO Manager OS Command Injection

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

πŸ“… Published: Feb. 13, 2025, 9:35 p.m. πŸ”„ Last Modified: April 23, 2025, 6:45 p.m.

5.1

CVSS4.0

CVE-2025-23411 - mySCADA myPRO Manager Cross-Site Request Forgery

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.

πŸ“… Published: Feb. 13, 2025, 9:33 p.m. πŸ”„ Last Modified: March 4, 2025, 8:59 p.m.

9.2

CVSS4.0

CVE-2025-22896 - mySCADA myPRO Manager Cleartext Storage of Sensitive Information

mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

πŸ“… Published: Feb. 13, 2025, 9:31 p.m. πŸ”„ Last Modified: March 4, 2025, 8:59 p.m.

10

CVSS4.0

CVE-2025-24865 - mySCADA myPRO Manager Missing Authentication for Critical Function

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

πŸ“… Published: Feb. 13, 2025, 9:29 p.m. πŸ”„ Last Modified: March 4, 2025, 8:59 p.m.

8.7

CVSS4.0

CVE-2025-24861 - Outback Power Mojave Inverter Command Injection

An attacker may inject commands via specially-crafted post requests.

πŸ“… Published: Feb. 13, 2025, 9:20 p.m. πŸ”„ Last Modified: March 4, 2025, 7:24 p.m.

8.7

CVSS4.0

CVE-2025-25281 - Outback Power Mojave Inverter Exposure of Sensitive Information to an Unauthorized Actor

An attacker may modify the URL to discover sensitive information about the target network.

πŸ“… Published: Feb. 13, 2025, 9:18 p.m. πŸ”„ Last Modified: April 10, 2025, 7:40 p.m.

8.7

CVSS4.0

CVE-2025-26473 - Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings

The Mojave Inverter uses the GET method for sensitive information.

πŸ“… Published: Feb. 13, 2025, 9:17 p.m. πŸ”„ Last Modified: March 19, 2025, 10:34 a.m.

9.3

CVSS4.0

CVE-2025-1283 - Dingtian DT-R0 Series Authentication Bypass Using an Alternate Path or Channel

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

πŸ“… Published: Feb. 13, 2025, 9:11 p.m. πŸ”„ Last Modified: April 10, 2025, 6:55 p.m.
Total resulsts: 346573
Page 6476 of 34,658
Β« previous page Β» next page
Filters