Show filters
350,190 Total Results
Displaying 401-410 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2025-25794
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
0
Attacker Value
Unknown
CVE-2025-25793
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
0
Attacker Value
Unknown
CVE-2025-25792
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.
0
Attacker Value
Unknown
CVE-2025-25791
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.
0
Attacker Value
Unknown
CVE-2025-25790
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
0
Attacker Value
Unknown
CVE-2025-25789
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
0
Attacker Value
Unknown
CVE-2025-25785
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.
0
Attacker Value
Unknown
CVE-2025-25784
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
0
Attacker Value
Unknown
CVE-2025-25783
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.
0
Attacker Value
Unknown
CVE-2025-1716
Disclosure Date: February 26, 2025 (last updated February 27, 2025)
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.
0