5.9

CVSS3.1

CVE-2025-52997 - File Browser Insecurely Handles Passwords

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-f…

πŸ“… Published: June 30, 2025, 8:05 p.m. πŸ”„ Last Modified: June 30, 2025, 8:26 p.m.

3.1

CVSS3.1

CVE-2025-52996 - File Browser's Password Protection of Links Vulnerable to Bypass

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file throug…

πŸ“… Published: June 30, 2025, 7:58 p.m. πŸ”„ Last Modified: June 30, 2025, 8:26 p.m.

8.1

CVSS3.1

CVE-2025-52995 - File Browser vulnerable to command execution allowlist bypass

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.10, the implementation of the allowlist is erroneous, allowing a user to execute more shell commands than they are authorized for.…

πŸ“… Published: June 30, 2025, 7:57 p.m. πŸ”„ Last Modified: June 30, 2025, 8:25 p.m.

4.5

CVSS3.1

CVE-2025-52901 - File Browser allows sensitive data to be transferred in URL

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier will get leaked to any…

πŸ“… Published: June 30, 2025, 7:56 p.m. πŸ”„ Last Modified: June 30, 2025, 8:25 p.m.

8.8

CVSS3.1

CVE-2025-36593 -

Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to forge a valid protocol accept message in response to a failed …

πŸ“… Published: June 30, 2025, 6:29 p.m. πŸ”„ Last Modified: July 1, 2025, 3:55 a.m.

6.9

CVSS4.0

CVE-2025-6925 - Dromara RuoYi-Vue-Plus Mail MailController.java path traversal

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath l…

πŸ“… Published: June 30, 2025, 6:02 p.m. πŸ”„ Last Modified: June 30, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-6917 - code-projects Online Hotel Booking registration.php sql injection

A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The manipulation of the argument uname leads to sql injection. The attack can be initiated remotely. The exploit has been…

πŸ“… Published: June 30, 2025, 5:32 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

8.7

CVSS4.0

CVE-2025-52898 - Frappe account takeover via password reset token leakage

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way. Frappe Cloud users a…

πŸ“… Published: June 30, 2025, 5:19 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

8.6

CVSS4.0

CVE-2025-52896 - Frappe authenticated XSS via data import

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There are no workarounds f…

πŸ“… Published: June 30, 2025, 5:12 p.m. πŸ”„ Last Modified: June 30, 2025, 8:39 p.m.

8.7

CVSS4.0

CVE-2025-52895 - Frappe possibility of SQL injection due to improper validations

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3 and 15.58.0. There ar…

πŸ“… Published: June 30, 2025, 5:05 p.m. πŸ”„ Last Modified: June 30, 2025, 8:40 p.m.
Total resulsts: 300073
Page 15 of 30,008
Β« previous page Β» next page
Filters