8.7

CVSS3.1

CVE-2025-25018 - Kibana Stored Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

πŸ“… Published: Oct. 10, 2025, 9:50 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:51 a.m.

3.7

CVSS3.1

CVE-2025-52634 - HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AIONΒ This issue affects HCL AION: 2.0.

πŸ“… Published: Oct. 10, 2025, 9:40 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:40 a.m.

8.2

CVSS3.1

CVE-2025-52650 - HCL AION is susceptible to Inline script execution allowed in CSP vulnerability

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

πŸ“… Published: Oct. 10, 2025, 9:30 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:30 a.m.

4.8

CVSS4.0

CVE-2025-41089 - Reflected Cross-Site Scripting (XSS) in CMS

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock'…

πŸ“… Published: Oct. 10, 2025, 9:19 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:19 a.m.

5.1

CVSS4.0

CVE-2025-41088 - Stored Cross-Site Scripting (XSS) in CMS

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text…

πŸ“… Published: Oct. 10, 2025, 9:17 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:19 a.m.

3.1

CVSS3.1

CVE-2025-52655 - HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.

πŸ“… Published: Oct. 10, 2025, 8:55 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 8:55 a.m.

5.1

CVSS4.0

CVE-2025-40640 - Multiple vulnerabilities in Energy CRM by Status Tracker

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to β€œ/crm/create_invoice_submit.php”, using the β€œcustomerName_0” parameter. This vulnerability could allow a …

πŸ“… Published: Oct. 10, 2025, 8:19 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 1:58 p.m.

7.1

CVSS3.1

CVE-2025-21050 -

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

πŸ“… Published: Oct. 10, 2025, 6:41 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:41 a.m.

4

CVSS3.1

CVE-2025-21070 -

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

πŸ“… Published: Oct. 10, 2025, 6:33 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:33 a.m.

4

CVSS3.1

CVE-2025-21069 -

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

πŸ“… Published: Oct. 10, 2025, 6:33 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:33 a.m.
Total resulsts: 313734
Page 15 of 31,374
Β« previous page Β» next page
Filters