6.5

CVSS3.1

CVE-2025-60868 -

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollu…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

0.0

CVE-2025-55903 -

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 7:19 p.m.

0.0

CVE-2025-60305 -

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

0.0

CVE-2025-60307 -

code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2025-61152 -

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthori…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.

9.3

CVSS4.0

CVE-2025-61928 - Better Auth: Unauthenticated API key creation through api-key plugin

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null :…

πŸ“… Published: Oct. 9, 2025, 9:24 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:24 p.m.

4.6

CVSS4.0

CVE-2025-61926 - Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and …

πŸ“… Published: Oct. 9, 2025, 9:20 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 11:17 a.m.

8.7

CVSS4.0

CVE-2016-15047 - AVTECH CloudSetup.cgi Authenticated Command Injection

AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke…

πŸ“… Published: Oct. 9, 2025, 9:10 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:10 p.m.

4.8

CVSS4.0

CVE-2025-62240 -

Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbi…

πŸ“… Published: Oct. 9, 2025, 9:08 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 2:26 p.m.

6.5

CVSS3.1

CVE-2025-59286 - Copilot Spoofing Vulnerability

Copilot Spoofing Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.
Total resulsts: 313754
Page 22 of 31,376
Β« previous page Β» next page
Filters