6.5

CVSS3.1

CVE-2025-40919 - Authen::DigestMD5 versions 0.01 through 0.04 for Perl generate the cnonce insecurely

Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not le…

📅 Published: July 16, 2025, 2:04 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

5.3

CVSS3.1

CVE-2025-3871 - Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may e…

📅 Published: July 16, 2025, 2 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

6.5

CVSS3.1

CVE-2025-40918 - Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed,…

📅 Published: July 16, 2025, 2 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

6.9

CVSS3.1

CVE-2025-53924 - Emlog vulnerable to stored Cross-site Scripting in links functionality

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter …

📅 Published: July 16, 2025, 1:55 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.

8.2

CVSS3.1

CVE-2025-53923 - Emlog vulnerable to reflected Cross-site Scripting in admin panel

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keywor…

📅 Published: July 16, 2025, 1:53 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-53892 - Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerr…

Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails …

📅 Published: July 16, 2025, 1:42 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

8.6

CVSS3.1

CVE-2025-40776 - Birthday Attack against Resolvers supporting ECS

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

📅 Published: July 16, 2025, 1:41 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

2.4

CVSS3.1

CVE-2025-53840 - Icinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be …

📅 Published: July 16, 2025, 1:34 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.

7.3

CVSS3.1

CVE-2025-40923 - Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it…

📅 Published: July 16, 2025, 1:05 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

10

CVSS4.0

CVE-2025-34300 - Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

📅 Published: July 16, 2025, 12:57 p.m. 🔄 Last Modified: July 16, 2025, 3:15 p.m.
Total resulsts: 302319
Page 17 of 30,232
« previous page » next page
Filters