3.5

CVSS3.1

CVE-2025-62780 - changedetection.io vulnerable to stored XSS in Watch update via API

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions prior to 0.50.34 due to insufficient security checks. Two scenarios are possible. In the first, an attacker can insert a new watch wit…

πŸ“… Published: Nov. 10, 2025, 9:18 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-64167 - Combodo iTop vulnerable to reflected XSS in webservices/export.php

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use export-v2.php instead.

πŸ“… Published: Nov. 10, 2025, 9:15 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 1:37 p.m.

8.7

CVSS3.1

CVE-2025-49145 - iTop admin can drop iTop database using webhooks

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.

πŸ“… Published: Nov. 10, 2025, 9:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 1:37 p.m.

4.3

CVSS3.1

CVE-2025-48878 - Combodo iTop vulnerable to IDOR with ModuleInstallation object

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version 3.2.2 fixes the issue.

πŸ“… Published: Nov. 10, 2025, 8:43 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 1:38 p.m.

8.8

CVSS3.1

CVE-2025-48065 - Combodo iTop vulnerable to reflected XSS via objection edition form error

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

πŸ“… Published: Nov. 10, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:12 p.m.

8.5

CVSS3.1

CVE-2025-48055 - Combodo iTop has stored XSS in user portal's browse brick

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.

πŸ“… Published: Nov. 10, 2025, 8:33 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:12 p.m.

4.2

CVSS3.1

CVE-2025-12729 -

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Nov. 10, 2025, 8 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 5:26 p.m.

4.2

CVSS3.1

CVE-2025-12728 -

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Nov. 10, 2025, 8 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 2:59 p.m.

7.5

CVSS3.1

CVE-2025-12726 -

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Nov. 10, 2025, 8 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:46 p.m.

8.8

CVSS3.1

CVE-2025-12727 - chromium-browser: Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Nov. 10, 2025, 8 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:46 p.m.
Total resulsts: 349182
Page 3087 of 34,919
Β« previous page Β» next page
Filters