2.3

CVSS4.0

CVE-2025-32700 - AbuseFilter log interfaces expose global private and hidden filters when central DB is not available

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExam…

πŸ“… Published: April 10, 2025, 6:31 p.m. πŸ”„ Last Modified: April 10, 2025, 6:31 p.m.

2.1

CVSS4.0

CVE-2025-32699 - Potential javascript injection attack enabled by Unicode normalization in Action API

Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.

πŸ“… Published: April 10, 2025, 6:30 p.m. πŸ”„ Last Modified: April 10, 2025, 6:30 p.m.

2.1

CVSS4.0

CVE-2025-32698 - LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/LogPager.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.

πŸ“… Published: April 10, 2025, 6:29 p.m. πŸ”„ Last Modified: April 10, 2025, 6:29 p.m.

0

CVSS4.0

CVE-2025-32697 - Cascading protection is not preventing file reversions

Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php. This issue affects MediaWiki: …

πŸ“… Published: April 10, 2025, 6:29 p.m. πŸ”„ Last Modified: April 10, 2025, 6:29 p.m.

0

CVSS4.0

CVE-2025-32696 - "reupload-own" restriction can be bypassed by reverting file

Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.

πŸ“… Published: April 10, 2025, 6:28 p.m. πŸ”„ Last Modified: April 10, 2025, 6:28 p.m.

0

CVSS4.0

CVE-2025-3469 - i18n XSS vulnerability in HTMLMultiSelectField when sections are used

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, …

πŸ“… Published: April 10, 2025, 6:28 p.m. πŸ”„ Last Modified: April 10, 2025, 6:28 p.m.

5.3

CVSS3.1

CVE-2025-22232 - Spring Cloud Config Server May Not Use Vault Token Sent By Clients

Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKENΒ header when making requests to Vault. Your application may be affected by this if the following are true: * You have Spring Vault on the classpath of your Spring Cloud Config Server and * You are using t…

πŸ“… Published: April 10, 2025, 5:26 p.m. πŸ”„ Last Modified: April 10, 2025, 6:15 p.m.

2.7

CVSS3.1

CVE-2025-24866 - Unauthorized Access to User Activity Logs API by delegated granular administration roles

Mattermost versions 9.11.x <= 9.11.8Β  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.

πŸ“… Published: April 10, 2025, 3:33 p.m. πŸ”„ Last Modified: April 10, 2025, 4:15 p.m.

1.8

CVSS4.0

CVE-2025-32382 - Snowflake credentials logged by the Metabase backend

Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge older Snowflake connection details from the appli…

πŸ“… Published: April 10, 2025, 2:40 p.m. πŸ”„ Last Modified: April 10, 2025, 3:23 p.m.

6.1

CVSS3.1

CVE-2025-32027 - Yii does not prevent XSS in scenarios where fallback error renderer is used

Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.

πŸ“… Published: April 10, 2025, 2:32 p.m. πŸ”„ Last Modified: April 10, 2025, 3:16 p.m.
Total resulsts: 289570
Page 1 of 28,957
Β» next page
Filters