6.9

CVSS3.1

CVE-2025-53924 - Emlog vulnerable to stored Cross-site Scripting in links functionality

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter …

📅 Published: July 16, 2025, 1:55 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.

8.2

CVSS3.1

CVE-2025-53923 - Emlog vulnerable to reflected Cross-site Scripting in admin panel

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keywor…

📅 Published: July 16, 2025, 1:53 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-53892 - Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerr…

Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails …

📅 Published: July 16, 2025, 1:42 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

8.6

CVSS3.1

CVE-2025-40776 - Birthday Attack against Resolvers supporting ECS

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

📅 Published: July 16, 2025, 1:41 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

2.4

CVSS3.1

CVE-2025-53840 - Icinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be …

📅 Published: July 16, 2025, 1:34 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

7.3

CVSS3.1

CVE-2025-40923 - Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it…

📅 Published: July 16, 2025, 1:05 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

10

CVSS4.0

CVE-2025-34300 - Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

📅 Published: July 16, 2025, 12:57 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.

5.1

CVSS4.0

CVE-2025-53758 - Default Credential Vulnerability in Digisol DG-GR6821AC Router

This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the hardcoded default credenti…

📅 Published: July 16, 2025, 11:29 a.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

9.3

CVSS3.1

CVE-2025-24759 - WordPress WP-BusinessDirectory <= 3.1.3 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory allows Blind SQL Injection. This issue affects WP-BusinessDirectory: from n/a through 3.1.3.

📅 Published: July 16, 2025, 11:28 a.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

8.8

CVSS3.1

CVE-2025-24777 - WordPress Hillter theme <= 3.0.7 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7.

📅 Published: July 16, 2025, 11:28 a.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.
Total resulsts: 302285
Page 14 of 30,229
« previous page » next page
Filters