9

CVSS3.1

CVE-2025-55244 - Azure Bot Service Elevation of Privilege Vulnerability

Azure Bot Service Elevation of Privilege Vulnerability

๐Ÿ“… Published: Sept. 4, 2025, 11:09 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 5:01 p.m.

6.1

CVSS3.1

CVE-2025-55305 - Electron is vulnerable to Code Injection via resource modification

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impactsโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 11:05 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 11:05 p.m.

5.1

CVSS4.0

CVE-2025-55209 - FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asteriskยฉ (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panelโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 10:50 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:47 p.m.

9.3

CVSS3.1

CVE-2025-58361 - Promptcraft Forge Studio's incomplete URL check is vulnerable to XSS via SVG

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 7:43 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:47 p.m.

7.8

CVSS3.1

CVE-2025-32322 -

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. Useโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 7:39 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 6:59 p.m.

8.2

CVSS3.1

CVE-2025-58353 - Promptcraft Forge Studio: Complete Sanitizer Bypass Enables XSS via Overlapping Patterns

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists such as r`eplace(/javascript:/gi, '')`. Because the package uses multi-character tokens and each replacemeโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 7:39 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:47 p.m.

0.0

CVE-2025-26439 -

In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User iโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 7:28 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 7:28 p.m.

7.8

CVSS3.1

CVE-2025-26431 -

In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 7:28 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:55 a.m.

3.3

CVSS3.1

CVE-2025-26419 -

In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: Sept. 4, 2025, 7:28 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:55 a.m.

6.2

CVSS3.1

CVE-2024-40664 -

In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 4, 2025, 7:28 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 2:03 p.m.
Total resulsts: 309436
Page 113 of 30,944
ยซ previous page ยป next page
Filters