6.1

CVSS3.1

CVE-2025-60374 -

Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A differ…

📅 Published: Oct. 14, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-56747 -

Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions without proper role validation, allowing unauthorized course creation and management.

📅 Published: Oct. 14, 2025, midnight 🔄 Last Modified: Oct. 21, 2025, 2:39 p.m.

7.5

CVSS3.1

CVE-2025-60536 -

An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file.

📅 Published: Oct. 14, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-11731 - Libxslt: type confusion in exsltfuncresultcompfunction of libxslt

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected…

📅 Published: Oct. 14, 2025, midnight 🔄 Last Modified: April 27, 2026, 8:05 p.m.

5.5

CVSS4.0

CVE-2025-62365 - LibreNMS vulnerable to Reflected-XSS in `report_this` function

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in a href environment)…

📅 Published: Oct. 13, 2025, 9:43 p.m. 🔄 Last Modified: Oct. 20, 2025, 5:27 p.m.

7.8

CVSS3.1

CVE-2025-62363 - yt-grabber-tui allows arbitrary code execution via configurable yt-dlp path

yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executable via the path_to_yt_dlp configuration setting. An attacker with write access to the configuration file or the filesys…

📅 Published: Oct. 13, 2025, 9:37 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-62362 - Name and e-mail of employee that has done a publication is discoverable in gpp-burgerportaal

gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information d…

📅 Published: Oct. 13, 2025, 9:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-62361 - WeGIA Open Redirect Vulnerability in `control.php` endpoint `nextPage` parameter (metodo=listarTodo…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified in the control.php endpoint of the WeGIA application, specifically in the nextPage parameter (metodo=listarTodos nomeClasse=AlmoxarifeControl…

📅 Published: Oct. 13, 2025, 9:27 p.m. 🔄 Last Modified: Oct. 21, 2025, 1:10 p.m.

9.4

CVSS4.0

CVE-2025-62360 - WeGIA SQL Injection via 'id_dependente' param at endpoint `/html/funcionario/dependente_documento.p…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to…

📅 Published: Oct. 13, 2025, 9:24 p.m. 🔄 Last Modified: Oct. 21, 2025, 1:10 p.m.

4.8

CVSS4.0

CVE-2025-62251 -

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensiti…

📅 Published: Oct. 13, 2025, 9:23 p.m. 🔄 Last Modified: Dec. 12, 2025, 8:37 p.m.
Total resulsts: 349182
Page 3455 of 34,919
« previous page » next page
Filters