CVE-2025-10405 2025-09-14 18:32:07 UTC | itsourcecode Baptism Information Management System listbaptism.php sql injection | MEDIUM 6.9 |
CVE-2025-10404 2025-09-14 18:02:08 UTC | itsourcecode Baptism Information Management System rptbaptismal.php sql injection | MEDIUM 6.9 |
CVE-2025-10403 2025-09-14 17:32:07 UTC | PHPGurukul Beauty Parlour Management System view-enquiry.php sql injection | MEDIUM 6.9 |
CVE-2025-6051 2025-09-14 17:03:03 UTC | Regular Expression Denial of Service (ReDoS) in huggingface/transformers | MEDIUM 5.3 |
CVE-2025-10402 2025-09-14 16:32:07 UTC | PHPGurukul Beauty Parlour Management System readenq.php sql injection | MEDIUM 6.9 |
CVE-2025-10401 2025-09-14 15:32:06 UTC | D-Link DIR-823x diag_ping command injection | MEDIUM 5.3 |
CVE-2025-10400 2025-09-14 14:02:07 UTC | SourceCodester Food Ordering Management System ticket-message.php sql injection | MEDIUM 5.3 |
CVE-2025-10399 2025-09-14 13:02:06 UTC | Korzh EasyQuery Query Builder UI fetch sql injection | MEDIUM 5.3 |
CVE-2025-0164 2025-09-14 12:57:32 UTC | IBM QRadar SIEM information disclosure | LOW 2.3 |
CVE-2025-36035 2025-09-14 12:52:49 UTC | IBM PowerVM Hypervisor denial of service | MEDIUM 6.7 |
CVE-2025-10204 2025-09-14 12:43:30 UTC | Unauth Admin Reset Password on AC Smart II | HIGH 7.1 |
CVE-2025-10398 2025-09-14 12:02:07 UTC | fcba_zzm ics-park Smart Park Management System FileUploadUtils.java unrestricted upload | MEDIUM 5.3 |
CVE-2025-10397 2025-09-14 11:02:06 UTC | Magicblack MacCMS API server-side request forgery | MEDIUM 5.1 |
CVE-2025-10396 2025-09-14 08:32:07 UTC | SourceCodester Pet Grooming Management Software edit_role.php sql injection | MEDIUM 6.9 |
CVE-2025-10395 2025-09-14 08:02:06 UTC | Magicblack MacCMS Scheduled Task col_url server-side request forgery | MEDIUM 5.1 |
CVE-2025-10394 2025-09-14 06:32:06 UTC | fcba_zzm ics-park Smart Park Management System Scheduled Task JobController.java code injection | MEDIUM 5.1 |
CVE-2025-10393 2025-09-14 06:02:07 UTC | miurla morphic HTTP Status Code 3xx advanced-search fetchHtml server-side request forgery | MEDIUM 5.3 |
CVE-2025-10392 2025-09-14 05:32:06 UTC | Mercury KM08-708H GiGA WiFi Wave2 HTTP Header stack-based overflow | CRITICAL 9.3 |
CVE-2025-10391 2025-09-14 05:02:07 UTC | CRMEB OutAccountServices.php testOutUrl server-side request forgery | MEDIUM 5.3 |
CVE-2025-59363 2025-09-14 04:51:44 UTC | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), | HIGH 7.7 |
CVE-2025-10390 2025-09-14 04:32:05 UTC | CRMEB UserAddressServices.php editAddress improper authorization | MEDIUM 5.3 |
CVE-2025-10389 2025-09-14 04:02:06 UTC | CRMEB Administrator Password SystemAdminServices.php save improper authorization | MEDIUM 5.3 |
CVE-2025-10388 2025-09-14 03:32:07 UTC | Selleo Mentingo Create New Course Basic Settings enroll-course cross site scripting | MEDIUM 5.1 |
CVE-2025-10387 2025-09-14 03:02:06 UTC | codesiddhant Jasmin Ransomware handshake.php sql injection | MEDIUM 5.3 |
CVE-2025-10386 2025-09-14 01:32:07 UTC | Yida ECMS Consulting Enterprise Management System POST Request login.do cross site scripting | MEDIUM 5.3 |
CVE-2025-10385 2025-09-14 01:02:06 UTC | Mercury KM08-708H GiGA WiFi Wave2 mcr_setSysAdm sub_450B2C buffer overflow | HIGH 8.7 |
CVE-2024-0564 2025-09-14 00:09:20 UTC | Kernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplication | MEDIUM 5.3 |
CVE-2025-10384 2025-09-13 19:32:07 UTC | yangzongzhuan RuoYi Role cancelAll improper authorization | MEDIUM 5.3 |
CVE-2025-10374 2025-09-13 19:02:07 UTC | Shenzhen Sixun Business Management System OperatorStop improper authorization | MEDIUM 6.9 |
CVE-2025-10373 2025-09-13 18:32:07 UTC | Portabilis i-Educar educar_turma_tipo_cad.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10372 2025-09-13 18:02:05 UTC | Portabilis i-Educar educar_modulo_cad.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10371 2025-09-13 17:32:06 UTC | eCharge Hardy Barth Salia PLCC api.php unrestricted upload | MEDIUM 6.9 |
CVE-2025-10370 2025-09-13 17:02:07 UTC | MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10369 2025-09-13 16:32:07 UTC | MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10368 2025-09-13 15:32:06 UTC | MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting | MEDIUM 5.1 |
CVE-2025-9135 2025-09-13 15:05:00 UTC | Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android application components | MEDIUM 4.8 |
CVE-2025-10367 2025-09-13 14:02:07 UTC | MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10366 2025-09-13 13:32:06 UTC | MiczFlor RPi-Jukebox-RFID inc.setWlanIpMail.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10359 2025-09-13 13:02:05 UTC | Wavlink WL-WN578W2 wireless.cgi sub_404DBC os command injection | MEDIUM 6.9 |
CVE-2024-1394 2025-09-13 12:59:13 UTC | Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads | HIGH 7.5 |
CVE-2025-10358 2025-09-13 08:02:06 UTC | Wavlink WL-WN578W2 wireless.cgi sub_404850 os command injection | MEDIUM 6.9 |
CVE-2025-4234 2025-09-13 03:55:40 UTC | Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials | LOW 2.4 |
CVE-2025-36222 2025-09-13 03:55:39 UTC | IBM Fusion insecure default configuration | HIGH 8.7 |
CVE-2025-55319 2025-09-13 03:55:38 UTC | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability | HIGH 8.8 |
CVE-2024-47120 2025-09-13 03:55:37 UTC | IBM Security Verify Information Queue code execution | MEDIUM 6.4 |
CVE-2025-21043 2025-09-13 03:55:36 UTC | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | HIGH 8.8 |
CVE-2025-21042 2025-09-13 03:55:35 UTC | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | HIGH 8.8 |
CVE-2025-27234 2025-09-13 03:55:35 UTC | Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0. | HIGH 7.3 |
CVE-2025-27240 2025-09-13 03:55:34 UTC | Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host | HIGH 7.5 |
CVE-2025-4235 2025-09-13 03:55:32 UTC | User-ID Credential Agent: Cleartext Exposure of Service Account password | MEDIUM 5.8 |
CVE-2025-10340 2025-09-13 02:32:05 UTC | WhatCD Gazelle Commit Message change_log.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10332 2025-09-13 02:02:06 UTC | cdevroe unmark info.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10331 2025-09-13 01:02:07 UTC | cdevroe unmark Marks.php cross site scripting | MEDIUM 5.1 |
CVE-2025-10330 2025-09-12 23:02:07 UTC | cdevroe unmark searchform.php cross site scripting | MEDIUM 5.3 |
CVE-2025-10329 2025-09-12 22:02:06 UTC | cdevroe unmark Marks.php server-side request forgery | MEDIUM 5.3 |
CVE-2025-10328 2025-09-12 21:32:09 UTC | MiczFlor RPi-Jukebox-RFID playsinglefile.php os command injection | MEDIUM 5.3 |
CVE-2025-10176 2025-09-12 21:25:26 UTC | The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File Deletion | HIGH 7.2 |
CVE-2025-10327 2025-09-12 21:02:06 UTC | MiczFlor RPi-Jukebox-RFID shuffle.php os command injection | MEDIUM 5.3 |
CVE-2025-10326 2025-09-12 20:32:05 UTC | MiczFlor RPi-Jukebox-RFID single.php os command injection | MEDIUM 5.3 |
CVE-2025-10325 2025-09-12 20:25:31 UTC | Wavlink WL-WN578W2 login.cgi sub_401BA4 command injection | MEDIUM 5.3 |
CVE-2025-45587 2025-09-12 20:13:34 UTC | A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
CVE-2025-45586 2025-09-12 20:13:08 UTC | An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a crafted PUT request. | |
CVE-2025-45585 2025-09-12 20:12:38 UTC | Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the wifi_sta_ssid or wifi_ap_ssid parameters. | |
CVE-2025-45584 2025-09-12 20:11:59 UTC | Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication. | |
CVE-2024-4629 2025-09-12 20:11:27 UTC | Keycloak: potential bypass of brute force protection | MEDIUM 6.5 |
CVE-2024-4540 2025-09-12 20:11:26 UTC | Keycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookie | HIGH 7.5 |
CVE-2024-5967 2025-09-12 20:11:18 UTC | Keycloak: leak of configured ldap bind credentials through the keycloak admin console | LOW 2.7 |
CVE-2025-43795 2025-09-12 20:11:09 UTC | Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_SystemSettingsPortlet_redirect parameter.Open redirect vulnerability in the Instance Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_InstanceSettingsPortlet_redirect parameter.Open redirect vulnerability in the Site Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_site_admin_web_portlet_SiteSettingsPortlet_redirect parameter. | MEDIUM 5.1 |
CVE-2025-45583 2025-09-12 20:10:36 UTC | Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password. | |
CVE-2023-39418 2025-09-12 20:10:08 UTC | Postgresql: merge fails to enforce update or select row security policies | LOW 3.1 |
CVE-2023-4042 2025-09-12 20:10:04 UTC | Ghostscript: incomplete fix for cve-2020-16305 | MEDIUM 5.5 |
CVE-2023-6484 2025-09-12 20:09:36 UTC | Keycloak: log injection during webauthn authentication or registration | MEDIUM 5.3 |
CVE-2024-9355 2025-09-12 20:07:36 UTC | Golang-fips: golang fips zeroed buffer | MEDIUM 6.5 |
CVE-2024-9407 2025-09-12 20:07:35 UTC | Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction | MEDIUM 4.7 |
CVE-2024-9341 2025-09-12 20:07:33 UTC | Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library | MEDIUM 5.4 |
CVE-2024-8676 2025-09-12 20:07:25 UTC | Cri-o: checkpoint restore can be triggered from different namespaces | HIGH 7.4 |
CVE-2024-8883 2025-09-12 20:07:25 UTC | Keycloak: vulnerable redirect uri validation results in open redirec | MEDIUM 6.1 |
CVE-2024-8418 2025-09-12 20:07:17 UTC | Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service | HIGH 7.5 |
CVE-2024-8445 2025-09-12 20:07:17 UTC | 389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199) | MEDIUM 5.7 |
CVE-2024-7341 2025-09-12 20:07:13 UTC | Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters | HIGH 7.1 |
CVE-2024-6655 2025-09-12 20:07:08 UTC | Gtk3: gtk2: library injection from cwd | HIGH 7.0 |
CVE-2024-6239 2025-09-12 20:07:05 UTC | Poppler: pdfinfo: crash in broken documents when using -dests parameter | HIGH 7.5 |
CVE-2024-6237 2025-09-12 20:07:03 UTC | 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request | MEDIUM 6.5 |
CVE-2024-5953 2025-09-12 20:06:58 UTC | 389-ds-base: malformed userpassword hash may cause denial of service | MEDIUM 5.7 |
CVE-2025-0306 2025-09-12 20:06:05 UTC | Ruby: openssl: ruby marvin attack | HIGH 7.4 |
CVE-2024-3296 2025-09-12 20:05:20 UTC | Rust-openssl: timing based side-channel can lead to a bleichenbacher style attack | MEDIUM 5.9 |
CVE-2024-3056 2025-09-12 20:04:53 UTC | Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack | HIGH 7.7 |
CVE-2024-56826 2025-09-12 20:04:14 UTC | Openjpeg: heap buffer overflow in bin/common/color.c | MEDIUM 5.6 |
CVE-2024-11029 2025-09-12 20:03:32 UTC | Freeipa: administrative user data leaked through systemd journal | MEDIUM 5.5 |
CVE-2024-10234 2025-09-12 20:03:26 UTC | Wildfly: wildfly vulnerable to cross-site scripting (xss) | MEDIUM 6.1 |
CVE-2024-1062 2025-09-12 20:03:23 UTC | 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr) | MEDIUM 5.5 |
CVE-2024-1481 2025-09-12 20:03:21 UTC | Freeipa: specially crafted http requests potentially lead to denial of service | MEDIUM 5.3 |
CVE-2023-39329 2025-09-12 20:03:07 UTC | Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c | MEDIUM 6.5 |
CVE-2023-39328 2025-09-12 20:03:05 UTC | Openjpeg: denail of service via crafted image file | MEDIUM 5.5 |
CVE-2023-50782 2025-09-12 20:02:35 UTC | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 | HIGH 7.5 |
CVE-2023-47039 2025-09-12 20:02:33 UTC | Perl: perl for windows binary hijacking vulnerability | HIGH 7.8 |
CVE-2023-47038 2025-09-12 20:02:30 UTC | Perl: write past buffer end via illegal user-defined unicode property | HIGH 7.0 |
CVE-2024-2199 2025-09-12 20:00:31 UTC | 389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c | MEDIUM 5.7 |
CVE-2023-6927 2025-09-12 19:59:53 UTC | Keycloak: open redirect via "form_post.jwt" jarm response mode | MEDIUM 4.6 |
CVE-2023-5455 2025-09-12 19:59:50 UTC | Ipa: invalid csrf protection | MEDIUM 6.5 |