5.3

CVSS3.1

CVE-2025-9616 - PopAd <= 1.0.4 - Cross-Site Request Forgery to Settings Update

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the PopAd_reset_cookie_time function. This makes it possible for unauthenticated attackers to reset cookie time settings viโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 9:22 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:35 p.m.

8.6

CVSS3.1

CVE-2025-2411 - OTP Bypass in Akinsoft's TaskPano

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass.This issue affects TaskPano: from s1.06.04 before v1.06.06.

๐Ÿ“… Published: Sept. 4, 2025, 8:34 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 8:08 p.m.

4.7

CVSS3.1

CVE-2024-13073 - XSS in Akinsoft's TaskPano

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

๐Ÿ“… Published: Sept. 4, 2025, 8:31 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 8:08 p.m.

7.5

CVSS3.0

CVE-2025-6984 - Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, whiโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 8:07 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 8:07 p.m.

8.6

CVSS3.1

CVE-2025-2417 - OTP Bypass in Akinsoft's e-Mutabakat

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass.This issue affects e-Mutabakat: from 2.02.06 before v2.02.06.

๐Ÿ“… Published: Sept. 4, 2025, 7:44 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 8:07 p.m.

4.3

CVSS3.1

CVE-2024-13071 - XSS in Akinsoft's e-Mutabakat

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-Mutabakat allows Cross-Site Scripting (XSS).This issue affects e-Mutabakat: from 2.02.05 before v2.02.06.

๐Ÿ“… Published: Sept. 4, 2025, 7:40 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:35 p.m.

5.3

CVSS4.0

CVE-2025-9467 - Possibility to bypass file upload validation on the server-side

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 7.0.0 -โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 6:15 a.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:35 p.m.

7.8

CVSS3.1

CVE-2025-36887 -

In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 4, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 4:39 p.m.

7.8

CVSS3.1

CVE-2024-56190 -

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 4, 2025, 5:10 a.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2024-56189 -

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 4, 2025, 5:10 a.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 4:39 p.m.
Total resulsts: 309489
Page 135 of 30,949
ยซ previous page ยป next page
Filters