5.3

CVSS3.1

CVE-2025-48355 - WordPress ProveSource Social Proof plugin <= 3.0.5 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource Social Proof allows Retrieve Embedded Sensitive Data.This issue affects ProveSource Social Proof: from n/a through 3.0.5.

πŸ“… Published: Aug. 21, 2025, 3:27 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 3:27 a.m.

0.0

CVE-2025-43300 -

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.8, macOS Ventura 13.7.8, iPadOS 17.7.10, macOS Sequoia 15.6.1, iOS 18.6.2 and iPadOS 18.6.2. Processing a malicious image file may result in memory corruption. Apple is aware of a repo…

πŸ“… Published: Aug. 21, 2025, 12:27 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:27 a.m.

0.0

CVE-2025-24285 -

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite. Affected Products: UniFi Connect EV Station Lite (Version 1.5.1 and earlier) Mitigation: Update …

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27213 -

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect …

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-48978 -

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network. Affected Products: EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) Mitigation: Update the EdgeMAX EdgeS…

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27215 -

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.10.3 and earlier) UniFi Connect Display Cast Pro (Version 1…

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27214 -

A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) Mit…

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27216 -

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate privileges.

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

0.0

CVE-2025-27217 -

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.

πŸ“… Published: Aug. 21, 2025, 12:01 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:01 a.m.

5.3

CVSS4.0

CVE-2025-9264 - Xuxueli xxl-job Jobs JobInfoController.java remove resource injection

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource id…

πŸ“… Published: Aug. 20, 2025, 11:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:32 p.m.
Total resulsts: 306423
Page 1 of 30,643
Β» next page
Filters