Search

Search Results (316238 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-21062 1 Samsung 1 Smart Switch 2025-10-28 7.8 High
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
CVE-2025-47902 1 Microchip 2 Timeprovider 4100, Timeprovider 4100 Firmware 2025-10-28 8.8 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5.
CVE-2025-47901 1 Microchip 2 Timeprovider 4100, Timeprovider 4100 Firmware 2025-10-28 8.8 High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
CVE-2025-5496 1 Zohocorp 1 Manageengine Endpoint Central 2025-10-28 3.3 Low
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
CVE-2025-21064 1 Samsung 1 Smart Switch 2025-10-28 8.8 High
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
CVE-2025-30001 1 Apache 1 Streampark 2025-10-28 7.3 High
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
CVE-2025-60838 1 Mingsoft 1 Mcms 2025-10-28 6.5 Medium
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-9063 1 Rockwellautomation 2 Factorytalk View, Panelview Plus 2025-10-28 9.8 Critical
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.
CVE-2025-47900 1 Microchip 2 Timeprovider 4100, Timeprovider 4100 Firmware 2025-10-28 8.8 High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
CVE-2025-62579 2 Delta Electronics, Deltaww 2 Asdasoft, Asda Soft 2025-10-28 7.8 High
ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-36081 1 Ibm 1 Concert 2025-10-28 5.3 Medium
IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.
CVE-2025-62580 2 Delta Electronics, Deltaww 2 Asdasoft, Asda Soft 2025-10-28 7.8 High
ASDA-Soft Stack-based Buffer Overflow Vulnerability
CVE-2025-11619 1 Devolutions 1 Devolutions Server 2025-10-28 8.8 High
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.
CVE-2025-9064 1 Rockwellautomation 2 Factorytalk View, Factorytalk View Machine Edition 2025-10-28 9.1 Critical
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
CVE-2025-36083 1 Ibm 1 Concert 2025-10-28 6.2 Medium
IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.
CVE-2025-36085 1 Ibm 1 Concert 2025-10-28 5.4 Medium
IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2025-6601 1 Gitlab 1 Gitlab 2025-10-28 2.7 Low
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
CVE-2025-62779 1 Frappe 2 Frappe, Frappe Lms 2025-10-28 N/A
Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form.
CVE-2025-8709 2 Langchain, Langchain-ai 2 Langchain, Langchain 2025-10-28 7.3 High
A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters.
CVE-2025-12325 1 Sourcecodester 1 Best Salon Management System 2025-10-28 7.3 High
A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.