Search

Search Results (313018 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-36355 1 Ibm 2 Security Verify Access, Security Verify Access Docker 2025-10-06 8.5 High
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
CVE-2024-45551 1 Qualcomm 484 Aqt1000, Aqt1000 Firmware, Ar8035 and 481 more 2025-10-06 6.2 Medium
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
CVE-2024-45549 1 Qualcomm 320 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 317 more 2025-10-06 7.7 High
Information disclosure while creating MQ channels.
CVE-2025-36354 1 Ibm 2 Security Verify Access, Security Verify Access Docker 2025-10-06 7.3 High
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.
CVE-2025-11341 2025-10-06 7.3 High
A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
CVE-2025-11314 1 Tipray 1 Data Leakage Prevention System 2025-10-06 7.3 High
A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-11342 2025-10-06 4.7 Medium
A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-40675 1 Webkul 1 Bagisto 2025-10-06 6.1 Medium
A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
CVE-2025-21448 1 Qualcomm 538 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 535 more 2025-10-06 7.5 High
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21439 1 Qualcomm 50 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 47 more 2025-10-06 7.8 High
Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.
CVE-2025-21435 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2025-10-06 7.5 High
Transient DOS may occur while parsing extended IE in beacon.
CVE-2025-21434 1 Qualcomm 244 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 241 more 2025-10-06 7.5 High
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
CVE-2025-21430 1 Qualcomm 450 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 447 more 2025-10-06 7.5 High
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2025-21429 1 Qualcomm 364 9206 Lte Modem, 9206 Lte Modem Firmware, Apq8017 and 361 more 2025-10-06 7.5 High
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428 1 Qualcomm 138 9206 Lte Modem, 9206 Lte Modem Firmware, Apq8017 and 135 more 2025-10-06 7.5 High
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2025-40668 1 Tcman 1 Gim 2025-10-06 6.5 Medium
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To exploit the vulnerability the PasswordActual parameter must be empty.
CVE-2025-11315 1 Tipray 1 Data Leakage Prevention System 2025-10-06 7.3 High
A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. Performing manipulation of the argument sort results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-11318 1 Tipray 1 Data Leakage Prevention System 2025-10-06 7.3 High
A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of the argument File results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-40669 1 Tcman 1 Gim 2025-10-06 6.5 Medium
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.
CVE-2025-40670 1 Tcman 1 Gim 2025-10-06 8.8 High
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.