5.1

CVSS4.0

CVE-2025-62297 - Stored XSS in SOPlanning

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening edited page. This issue was fixed in version 1.55.

📅 Published: Nov. 20, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.1

CVSS4.0

CVE-2025-62296 - Stored XSS in SOPlanning

SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.

📅 Published: Nov. 20, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.1

CVSS4.0

CVE-2025-62295 - Stored XSS in SOPlanning

SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.

📅 Published: Nov. 20, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

8.7

CVSS4.0

CVE-2025-62294 - Predictable Generation of Password Recovery Token

SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time. This issue was fixed in version 1.55.

📅 Published: Nov. 20, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.3

CVSS4.0

CVE-2025-62293 - Broken Access Control in SOPlanning

SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status. This issue was fixed in version 1.55.

📅 Published: Nov. 20, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

9.3

CVSS4.0

CVE-2025-34320 - BASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCE

BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allows unauthenticated directory traversal sequences to cause the server to read arbitrary system files accessible to the account running the service. Retr…

📅 Published: Nov. 20, 2025, 3:31 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

1.9

CVSS4.0

CVE-2025-13425 - Denial of Service in OSV-SCALIBR

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of service) in OSV-SCALIBR.

📅 Published: Nov. 20, 2025, 3:30 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.9

CVSS3.1

CVE-2025-36161 - IBM Concert Software Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

📅 Published: Nov. 20, 2025, 3:26 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

7.2

CVSS3.1

CVE-2025-0645 - Arbitrary File Upload in Narkom Communication Technologies' Pyxis Signage

Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Pyxis Signage: through 31012025.

📅 Published: Nov. 20, 2025, 1:33 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

4.8

CVSS4.0

CVE-2025-13469 - Public Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scripting

A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstruct…

📅 Published: Nov. 20, 2025, 1:32 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319174
Page 26 of 31,918
« previous page » next page
Filters