CVE ID | Publié | Description | Score | Gravité | |
---|---|---|---|---|---|
CVE-2025-2775 |
2025-05-07 14h43 +00:00 |
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vu... |
9.3 |
Critique |
|
CVE-2025-2776 |
2025-05-07 14h50 +00:00 |
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vu... |
9.3 |
Critique |
|
CVE-2025-2777 |
2025-05-07 14h53 +00:00 |
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vu... |
9.3 |
Critique |
|
CVE-2025-47549 |
2025-05-07 14h20 +00:00 |
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF allows Upload a Web S... File Inclusion |
9.1 |
Critique |
|
CVE-2025-47649 |
2025-05-07 14h20 +00:00 |
Path Traversal vulnerability in ilmosys Open Close WooCommerce Store allows PHP Local File Inclusion... |
8.8 |
Haute |
|
CVE-2025-47657 |
2025-05-07 14h20 +00:00 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i... SQL Injection |
9.3 |
Critique |
|
CVE-2025-47462 |
2025-05-07 14h19 +00:00 |
Cross-Site Request Forgery (CSRF) vulnerability in Ohidul Islam Challan allows Privilege Escalation.... Cross-Site Request Forgery - CSRF |
8.8 |
Haute |
|
CVE-2025-47490 |
2025-05-07 14h19 +00:00 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i... SQL Injection |
8.5 |
Haute |
|
CVE-2025-4104 |
2025-05-07 09h21 +00:00 |
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing c... |
9.8 |
Critique |
|
CVE-2025-20979 |
2025-05-07 08h24 +00:00 |
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary co... |
8.4 |
Haute |