6.4

CVSS4.0

CVE-2025-53931 - WeGIA vulnerable to Stored Cross-Site Scripting via endpoint `adicionar_raca.php` parameter `raca`

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_raca.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inje…

📅 Published: July 16, 2025, 3:50 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

6.4

CVSS4.0

CVE-2025-53930 - WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint 'adicionar_especie.php' paramete…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_especie.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to i…

📅 Published: July 16, 2025, 3:49 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

6.4

CVSS4.0

CVE-2025-53929 - WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint `adicionar_cor.php` parameter `c…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cor.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to injec…

📅 Published: July 16, 2025, 3:44 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

6.1

CVSS3.1

CVE-2025-53926 - Emlog has Stored Cross-site Scripting vulnerability due to error

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefo…

📅 Published: July 16, 2025, 3:37 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

8.7

CVSS4.0

CVE-2025-5994 - Cache poisoning via the ECS-enabled Rebirthday Attack

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to ups…

📅 Published: July 16, 2025, 2:38 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

5.4

CVSS3.1

CVE-2025-53925 - Emlog has Stored Cross-site Scripting vulnerability in file upload functionality

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload an .s…

📅 Published: July 16, 2025, 2:21 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

7.1

CVSS3.1

CVE-2025-37104 - HPE Telco Service Orchestrator Software, Authenticated SQL Injection

A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clien…

📅 Published: July 16, 2025, 2:17 p.m. 🔄 Last Modified: July 17, 2025, 9:15 p.m.

6.5

CVSS3.1

CVE-2025-40913 - Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an in…

Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

📅 Published: July 16, 2025, 2:05 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

6.5

CVSS3.1

CVE-2025-40919 - Authen::DigestMD5 versions 0.01 through 0.04 for Perl generate the cnonce insecurely

Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not le…

📅 Published: July 16, 2025, 2:04 p.m. 🔄 Last Modified: July 16, 2025, 9:15 p.m.

5.3

CVSS3.1

CVE-2025-3871 - Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may e…

📅 Published: July 16, 2025, 2 p.m. 🔄 Last Modified: July 16, 2025, 2:58 p.m.
Total resulsts: 302337
Page 18 of 30,234
« previous page » next page
Filters