6.9

CVSS4.0

CVE-2025-62661 - Do permission checking when getting counts of global and local edits, new articles and thanks

Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension: fโ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 7:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-62249 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.Q3.2, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.โ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 6:12 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:39 p.m.

8.7

CVSS4.0

CVE-2025-11757 - Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key informatโ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 5:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-12031 - HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute

HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow readingย the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

๐Ÿ“… Published: Oct. 21, 2025, 5:22 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 8:10 p.m.

5.3

CVSS4.0

CVE-2025-8050 - External Control of File vulnerability has been discovered in opentext Flipper.

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.ย  The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

๐Ÿ“… Published: Oct. 21, 2025, 5:21 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 4:16 p.m.

9.3

CVSS4.0

CVE-2025-11534 - Authentication Bypass Using an Alternate Path or Channel in Raisecomm RAX701-GC Series

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

๐Ÿ“… Published: Oct. 21, 2025, 4:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-62605 - Mastodon quotes control can be bypassed

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2. Mastodon internallโ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 4:46 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 1:39 p.m.

6.9

CVSS4.0

CVE-2025-62598 - WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Paโ€ฆ

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to injectโ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 4:34 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 10:13 a.m.

6.9

CVSS4.0

CVE-2025-62597 - WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Paโ€ฆ

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to injectโ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 4:34 p.m. ๐Ÿ”„ Last Modified: Oct. 24, 2025, 3:43 p.m.

4.3

CVSS3.1

CVE-2025-62595 - Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the โ€ฆ

๐Ÿ“… Published: Oct. 21, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: Jan. 20, 2026, 2:45 p.m.
Total resulsts: 349182
Page 3355 of 34,919
ยซ previous page ยป next page
Filters