Common Vulnerabilities and Exposures (CVE)

CVE-2025-10592

Sep 17, 2025 14:01:25 UTC

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_fi...

CVE-2025-10534

Sep 17, 2025 14:01:05 UTC

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVE-2025-37128

Sep 17, 2025 14:00:38 UTC

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system oper...

CVE-2025-37129

Sep 17, 2025 13:59:59 UTC

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands ...

CVE-2025-34184

Sep 17, 2025 13:59:46 UTC

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HT...

CVE-2025-37127

Sep 17, 2025 13:59:02 UTC

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary comm...

CVE-2024-7341

Sep 17, 2025 13:58:21 UTC

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an att...

CVE-2025-34185

Sep 17, 2025 13:58:18 UTC

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information a...

CVE-2025-54391

Sep 17, 2025 13:57:52 UTC

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA ...

CVE-2025-37130

Sep 17, 2025 13:57:20 UTC

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying ...

CVE-2025-10564

Sep 17, 2025 13:56:26 UTC

A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_category. Performing manipulation of the argument ID results in sql injection. The attack is ...

CVE-2025-56263

Sep 17, 2025 13:54:59 UTC

by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of any size and type.

CVE-2025-10593

Sep 17, 2025 13:53:33 UTC

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is...

CVE-2025-10166

Sep 17, 2025 13:53:16 UTC

The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on use...

CVE-2025-57631

Sep 17, 2025 13:51:54 UTC

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module