CVE Alert: CVE-2025-26846
Vulnerability Summary: CVE-2025-26846 An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic...
Vulnerability Summary: CVE-2025-26846 An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic...
Vulnerability Summary: CVE-2025-26841 Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code...
Vulnerability Summary: CVE-2025-46718 sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6,...
Vulnerability Summary: CVE-2025-46717 sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6,...
Vulnerability Summary: CVE-2025-46737 SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway...
Vulnerability Summary: CVE-2025-46610 ARTEC EMA Mail 6.92 allows CSRF. Affected Endpoints: No affected endpoints listed. Published Date: 5/12/2025, 3:16:01 PM...
Vulnerability Summary: CVE-2025-46738 An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary...
Vulnerability Summary: CVE-2025-47578 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow...
Vulnerability Summary: CVE-2025-46611 Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via...
Vulnerability Summary: CVE-2025-46743 An authenticated user's token could be used by another source after the user had logged out prior...
Vulnerability Summary: CVE-2025-46742 Users who were required to change their password could still access system information before changing their password...
Vulnerability Summary: CVE-2025-44022 An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin...
Vulnerability Summary: CVE-2025-44830 EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface. Affected Endpoints: No affected...
Vulnerability Summary: CVE-2025-3632 IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of...
Vulnerability Summary: CVE-2025-46750 SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and...
Vulnerability Summary: CVE-2025-46741 A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred....
Vulnerability Summary: CVE-2025-46739 An unauthenticated user could discover account credentials via a brute-force attack without rate limiting Affected Endpoints: No...
Vulnerability Summary: CVE-2025-46740 An authenticated user without user administrative permissions could change the administrator Account Name. Affected Endpoints: No affected...
Vulnerability Summary: CVE-2025-45779 Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter....
Vulnerability Summary: CVE-2025-46746 An administrator could discover another account's credentials. Affected Endpoints: No affected endpoints listed. Published Date: 5/12/2025, 5:15:48...
Vulnerability Summary: CVE-2025-46749 An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to...
Vulnerability Summary: CVE-2025-46747 An authenticated user without user-management permissions could identify other user accounts. Affected Endpoints: No affected endpoints listed....
Vulnerability Summary: CVE-2025-46748 An authenticated user attempting to change their password could do so without using the current password. Affected...
Vulnerability Summary: CVE-2025-46745 An authenticated user without user-management permissions could view other users' account information. Affected Endpoints: No affected endpoints...