Aggregator
CVE-2025-41458 | Two App Studio Journey up to 5.5.9 cleartext storage
9 months ago
A vulnerability classified as problematic was found in Two App Studio Journey up to 5.5.9. This vulnerability affects unknown code. The manipulation leads to cleartext storage of sensitive information.
This vulnerability was named CVE-2025-41458. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2025-4130 | PAVO Pay prior 13.05.2025 hard-coded credentials
9 months ago
A vulnerability classified as critical has been found in PAVO Pay. This affects an unknown part. The manipulation leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2025-4130. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-4129 | PAVO Pay up to 13.05.2024 authorization
9 months ago
A vulnerability was found in PAVO Pay up to 13.05.2024. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to authorization bypass.
This vulnerability is handled as CVE-2025-4129. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5681 | Turtek Eyotek 11.03.2025 authorization
9 months ago
A vulnerability was found in Turtek Eyotek 11.03.2025. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to authorization bypass.
This vulnerability is known as CVE-2025-5681. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6235 | ExtremeControl up to 25.5.10 Login Interface cross site scripting
9 months ago
A vulnerability was found in ExtremeControl up to 25.5.10. It has been classified as problematic. Affected is an unknown function of the component Login Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-6235. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-41459 | Two App Studio Journey App up to 5.5.8 on iOS improper authentication
9 months ago
A vulnerability was found in Two App Studio Journey App up to 5.5.8 on iOS and classified as critical. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2025-41459. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13973 | Sophos Firewall up to 21.0 sql injection
9 months ago
A vulnerability has been found in Sophos Firewall up to 21.0 and classified as critical. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability was named CVE-2024-13973. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-43977 | com.skt.prod.dialer up to 12.5.0 on Android permission
9 months ago
A vulnerability, which was classified as critical, was found in com.skt.prod.dialer up to 12.5.0 on Android. This affects an unknown part. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2025-43977. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2025-43976 | com.enflick.android.tn2ndLine up to 24.17.1.0 on Android permission
9 months ago
A vulnerability, which was classified as critical, has been found in com.enflick.android.tn2ndLine up to 24.17.1.0 on Android. Affected by this issue is some unknown functionality. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2025-43976. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-44650 | Netgear R7000/EAX80 Configuration File bftpd.conf denial of service (EUVD-2025-22100)
9 months ago
A vulnerability classified as problematic was found in Netgear R7000 and EAX80. Affected by this vulnerability is an unknown functionality of the file bftpd.conf of the component Configuration File Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2025-44650. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-4040 | Turpak Automatic Station Monitoring System prior 5.0.6.51 authorization (EUVD-2025-22082)
9 months ago
A vulnerability classified as critical has been found in Turpak Automatic Station Monitoring System. Affected is an unknown function. The manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2025-4040. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2301 | Akbim Online Exam Registration prior 14.03.2025 authorization
9 months ago
A vulnerability was found in Akbim Online Exam Registration. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to authorization bypass.
The identification of this vulnerability is CVE-2025-2301. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46119 | CommScope Management Endpoint /admin/_cmdstat.jsp information disclosure
9 months ago
A vulnerability was found in CommScope Ruckus Unleashed. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/_cmdstat.jsp of the component Management Endpoint. The manipulation leads to information disclosure.
This vulnerability was named CVE-2025-46119. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-41100 | ParkingDoor 2016.08.11.1 improper validation of specified quantity in input
9 months ago
A vulnerability was found in ParkingDoor 2016.08.11.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to improper validation of specified quantity in input.
This vulnerability is uniquely identified as CVE-2025-41100. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-30192 | PowerDNS Recursor up to 5.0.11/5.1.5/5.2.3 ECS data authenticity
9 months ago
A vulnerability was found in PowerDNS Recursor up to 5.0.11/5.1.5/5.2.3 and classified as critical. Affected by this issue is some unknown functionality of the component ECS. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is handled as CVE-2025-30192. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46118 | CommScope Ruckus Unleashed/Ruckus ZoneDirector FTP hard-coded credentials
9 months ago
A vulnerability has been found in CommScope Ruckus Unleashed and Ruckus ZoneDirector and classified as critical. Affected by this vulnerability is an unknown functionality of the component FTP. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2025-46118. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46117 | CommScope Ruckus Unleashed/Ruckus ZoneDirector Restricted CLI ap_debug.sh command injection
9 months ago
A vulnerability, which was classified as critical, was found in CommScope Ruckus Unleashed and Ruckus ZoneDirector. Affected is an unknown function of the file ap_debug.sh of the component Restricted CLI. The manipulation leads to command injection.
This vulnerability is traded as CVE-2025-46117. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46116 | CommScope Ruckus Unleashed/Ruckus ZoneDirector CLI Command access control
9 months ago
A vulnerability, which was classified as critical, has been found in CommScope Ruckus Unleashed and Ruckus ZoneDirector. This issue affects some unknown processing of the component CLI Command Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-46116. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-7382 | Sophos Firewall up to 21.0 MR1 WebAdmin os command injection
9 months ago
A vulnerability classified as critical was found in Sophos Firewall up to 21.0 MR1. This vulnerability affects unknown code of the component WebAdmin. The manipulation leads to os command injection.
This vulnerability was named CVE-2025-7382. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com