6.5

CVSS3.1

CVE-2025-63608 -

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:44 a.m.

7.5

CVSS3.1

CVE-2025-61119 -

Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request parameters. Successful…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-61141 -

sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to sh -c without sanitization, allowing attackers to execute arbitrary commands.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.8

CVSS3.1

CVE-2025-61196 -

An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.5

CVSS3.1

CVE-2025-40103 - smb: client: Fix refcount leak for cifs_sb_tlink

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink Fix three refcount inconsistency issues related to `cifs_sb_tlink`. Comments for `cifs_sb_tlink` state that `cifs_put_tlink()` needs to be called after successful calls to `cifs_s…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

6.3

CVSS4.0

CVE-2025-62257 -

Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to …

πŸ“… Published: Oct. 29, 2025, 11:24 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 5:41 p.m.

7.5

CVSS3.1

CVE-2025-12466 - Simple OAuth (OAuth2) & OpenID Connect - Critical - Access bypass - SA-CONTRIB-2025-114

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.

πŸ“… Published: Oct. 29, 2025, 11:14 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:15 p.m.

6.1

CVSS3.1

CVE-2025-12083 - CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-113

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

πŸ“… Published: Oct. 29, 2025, 11:14 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2025-12082 - CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025-112

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

πŸ“… Published: Oct. 29, 2025, 11:14 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2025-10929 - Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111

Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.

πŸ“… Published: Oct. 29, 2025, 11:14 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.
Total resulsts: 317458
Page 122 of 31,746
Β« previous page Β» next page
Filters