0.0

CVE-2025-60305 -

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:21 p.m.

7.3

CVSS3.1

CVE-2025-60869 -

Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visi…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 2:51 p.m.

0.0

CVE-2025-60868 -

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollu…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 2 p.m.

9.9

CVSS3.1

CVE-2025-60306 -

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6 p.m.

0.0

CVE-2025-61319 -

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can b…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 1:51 p.m.

0.0

CVE-2025-55903 -

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 7:19 p.m.

4.3

CVSS3.1

CVE-2025-62292 -

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:17 a.m.

0.0

CVE-2025-61505 -

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could le…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:34 p.m.

9.3

CVSS4.0

CVE-2025-61928 - Better Auth: Unauthenticated API key creation through api-key plugin

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null :…

πŸ“… Published: Oct. 9, 2025, 9:24 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:24 p.m.

4.6

CVSS4.0

CVE-2025-61926 - Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and …

πŸ“… Published: Oct. 9, 2025, 9:20 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 11:17 a.m.
Total resulsts: 313677
Page 14 of 31,368
Β« previous page Β» next page
Filters