8.6

CVSS3.1

CVE-2025-27222 -

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any local server file th…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 4:57 p.m.

3.7

CVSS3.1

CVE-2025-11989 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

πŸ“… Published: Oct. 26, 2025, 11:33 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 2:44 p.m.

10

CVSS4.0

CVE-2025-12285 - Missing Initial Password Change

Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 26, 2025, 4:24 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:55 p.m.

6.9

CVSS4.0

CVE-2025-12284 - Lack of Input Validation

Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 26, 2025, 4:21 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:57 p.m.

10

CVSS4.0

CVE-2025-12275 - Mail Configuration File Manipulation + Command Execution

Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 26, 2025, 4:15 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:06 a.m.

6.9

CVSS4.0

CVE-2025-12278 - Logout Functionality not Working

Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 26, 2025, 4:14 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:58 p.m.

7.3

CVSS3.1

CVE-2025-8709 - SQL Injection in langchain-ai/langchain

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte…

πŸ“… Published: Oct. 26, 2025, 5:38 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 3:16 p.m.

6.1

CVSS3.1

CVE-2025-55757 - Extension - virtuemart.net - XSS in VirtueMart component 1.0.0 - 4.4.10 for Joomla

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

πŸ“… Published: Oct. 25, 2025, 6:34 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 4:35 a.m.

2.1

CVSS4.0

CVE-2025-12221 - CSRF Token not Properly Implemented

Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 25, 2025, 3:57 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:08 a.m.

10

CVSS4.0

CVE-2025-12220 - Busybox 1.31.1 - Multiple Known Vulnerabilities

Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 25, 2025, 3:53 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 3 p.m.
Total resulsts: 343975
Page 2763 of 34,398
Β« previous page Β» next page
Filters