CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.5

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

Published: Feb 03, 2025
Modified: Mar 04, 2025
EPSS: 20.80%
View Details
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.

Published: Feb 03, 2025
Modified: Mar 04, 2025
EPSS: 0.36%
View Details
8.8

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

Published: Feb 03, 2025
Modified: Mar 22, 2025
EPSS: 6.59%
View Details
9.8

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

Published: Jan 31, 2025
Modified: May 23, 2025
Product: openpanel openpanel
EPSS: 11.99%
View Details
7.5

An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.

Published: Jan 31, 2025
Modified: May 23, 2025
Product: openpanel openpanel
EPSS: 6.99%
View Details
9.1

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

Published: Jan 31, 2025
Modified: Oct 02, 2025
Product: openpanel openpanel
EPSS: 7.60%
View Details
7.5

The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin/#/login/ URI.

Published: Jan 29, 2025
Modified: Jan 31, 2025
EPSS: 9.17%
View Details
9.4

Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through

Published: Jan 29, 2025
EPSS: 1.82%
View Details
9.4

Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through

Published: Jan 29, 2025
EPSS: 0.19%
View Details
4.7

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…

Published: Jan 28, 2025
Modified: Nov 04, 2025
Product: pimcore pimcore
EPSS: 0.00%
View Details
2.4

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published: Jan 28, 2025
Modified: Nov 04, 2025
Product: pimcore pimcore
EPSS: 0.09%
View Details
10.0

Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.

Published: Jan 27, 2025
Modified: Feb 14, 2025
EPSS: 4.78%
View Details
5.4

silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on both the CMS and…

Published: Jan 14, 2025
EPSS: 2.29%
View Details
6.1

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

Published: Jan 14, 2025
Modified: Jun 06, 2025
Product: gestioip gestioip
EPSS: 0.39%
View Details
4.8

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

Published: Jan 14, 2025
Modified: Jun 06, 2025
Product: gestioip gestioip
EPSS: 0.37%
View Details
8.8

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.

Published: Jan 14, 2025
Modified: Jun 06, 2025
Product: gestioip gestioip
EPSS: 0.14%
View Details
4.8

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

Published: Jan 14, 2025
Modified: Jun 06, 2025
Product: gestioip gestioip
EPSS: 0.07%
View Details
9.8

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

Published: Jan 14, 2025
Modified: Jun 06, 2025
Product: gestioip gestioip
EPSS: 4.40%
View Details
6.3

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

Published: Jan 09, 2025
Modified: Sep 29, 2025
Product: bigantsoft bigant_office_messenger_5
EPSS: 0.38%
View Details
9.8

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

Published: Dec 31, 2024
Modified: May 17, 2025
Product: themehunk hunk_companion
EPSS: 91.68%
View Details
4.8

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Published: Dec 27, 2024
Modified: Jun 12, 2025
Product: wp-publications_project wp-publications
EPSS: 0.45%
View Details
4.3

A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

Published: Dec 26, 2024
Modified: Apr 03, 2025
Product: phpgurukul blood_bank_\&_donor_management_system
EPSS: 0.16%
View Details
3.7

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather…

Published: Dec 12, 2024
Modified: Dec 13, 2024
Product: ujcms ujcms
EPSS: 0.93%
View Details
6.3

A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…

Published: Dec 08, 2024
Modified: Dec 10, 2024
Product: tp-link vn020_f3v_firmware
EPSS: 1.42%
View Details