5.4

CVSS3.1

CVE-2025-64792 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-64575 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:55 p.m.

5.4

CVSS3.1

CVE-2025-64802 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:14 p.m.

5.4

CVSS3.1

CVE-2025-64793 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-64594 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:12 p.m.

5.4

CVSS3.1

CVE-2025-64614 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 5:39 p.m.

4.8

CVSS3.1

CVE-2025-64872 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they bro…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 5:32 p.m.

5.4

CVSS3.1

CVE-2025-64562 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, s…

📅 Published: Dec. 10, 2025, 6:22 p.m. 🔄 Last Modified: Dec. 12, 2025, 7:55 p.m.

7.3

CVSS4.0

CVE-2025-65199 - Windscribe for Linux 'changeMTU' local privilege escalation

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.

📅 Published: Dec. 10, 2025, 6:04 p.m. 🔄 Last Modified: Dec. 23, 2025, 3:27 p.m.

1.9

CVSS4.0

CVE-2025-5467 - Ubuntu Apport Insecure File Permissions Vulnerability

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

📅 Published: Dec. 10, 2025, 6 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:12 p.m.
Total resulsts: 349182
Page 2687 of 34,919
« previous page » next page
Filters