0.0

CVE-2025-60991 -

A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6 p.m.

0.0

CVE-2025-59687 -

IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:56 p.m.

0.0

CVE-2025-61045 -

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:06 p.m.

0.0

CVE-2025-57444 -

An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:28 p.m.

0.0

CVE-2025-61188 -

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:05 p.m.

0.0

CVE-2025-28357 -

A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:08 p.m.

0.0

CVE-2025-52041 -

In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the inventory_dimensions_dict parame…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:36 p.m.

0.0

CVE-2025-46205 -

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:16 p.m.

0.0

CVE-2025-57275 -

Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:56 p.m.

8.7

CVSS4.0

CVE-2025-24525 - Keysight Ixia Vision Product Family Use of Hard-coded Cryptographic Key

Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is availabl…

πŸ“… Published: Sept. 30, 2025, 11:04 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 11:04 p.m.
Total resulsts: 312441
Page 28 of 31,245
Β« previous page Β» next page
Filters