5.4

CVSS3.1

CVE-2024-42212 - HCL BigFix Compliance is affected by an improper or missing SameSite attribute

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

📅 Published: May 5, 2025, 6:40 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

5.4

CVSS3.1

CVE-2025-46559 - Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation allows malicious AiScr…

📅 Published: May 5, 2025, 6:38 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

7.2

CVSS3.1

CVE-2025-46340 - Misskey CSS Style Injection Vulnerability In `MkUrlPreview`

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the `MkUrlPreview` component. …

📅 Published: May 5, 2025, 6:35 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

6.9

CVSS4.0

CVE-2025-4283 - SourceCodester/oretnom23 Stock Management System Login.php sql injection

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. Th…

📅 Published: May 5, 2025, 6:31 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

2.1

CVSS4.0

CVE-2025-46553 - @misskey-dev/summaly Redirect Filter Bypass

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects…

📅 Published: May 5, 2025, 6:28 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

8.6

CVSS4.0

CVE-2025-46335 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon U…

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of use…

📅 Published: May 5, 2025, 6:23 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

8.8

CVSS3.1

CVE-2025-4279 - External image replace <= 1.0.8 - Authenticated (Contributor+) Arbitrary File Upload

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with contribu…

📅 Published: May 5, 2025, 6:22 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

8.9

CVSS4.0

CVE-2025-43852 - GHSL-2025-022_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , if model_name contains…

📅 Published: May 5, 2025, 6:21 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

8.9

CVSS4.0

CVE-2025-43851 - GHSL-2025-021_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , a new instance of Audi…

📅 Published: May 5, 2025, 6:21 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.

8.9

CVSS4.0

CVE-2025-43850 - GHSL-2025-020_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load t…

📅 Published: May 5, 2025, 6:20 p.m. 🔄 Last Modified: May 5, 2025, 8:54 p.m.
Total resulsts: 292808
Page 22 of 29,281
« previous page » next page
Filters