4.8

CVSS4.0

CVE-2025-62237 -

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via …

📅 Published: Oct. 10, 2025, 12:51 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:23 p.m.

4.8

CVSS4.0

CVE-2025-62238 -

Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbi…

📅 Published: Oct. 10, 2025, 12:33 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:17 p.m.

4.6

CVSS4.0

CVE-2025-62239 -

Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HT…

📅 Published: Oct. 10, 2025, 12:21 p.m. 🔄 Last Modified: Dec. 12, 2025, 6:12 p.m.

5.4

CVSS3.1

CVE-2025-7374 - WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and…

📅 Published: Oct. 10, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

6.4

CVSS3.1

CVE-2025-7781 - WP JobHunt <= 7.6 - Authenticated (Candidate+) Stored Cross-Site Scripting via ‘cs_job_title’

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘cs_job_title’ parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

📅 Published: Oct. 10, 2025, 11:17 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

5.3

CVSS3.1

CVE-2025-11579 - DoS via Out Of Memory Crash

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

📅 Published: Oct. 10, 2025, 11:15 a.m. 🔄 Last Modified: Jan. 16, 2026, 8:56 p.m.

8.4

CVSS4.0

CVE-2025-61864 -

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

📅 Published: Oct. 10, 2025, 11:05 a.m. 🔄 Last Modified: Oct. 27, 2025, 6:06 p.m.

5.4

CVSS3.1

CVE-2025-11190 - CVE-2025-11190

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

📅 Published: Oct. 10, 2025, 11:03 a.m. 🔄 Last Modified: Nov. 17, 2025, 2:50 p.m.

7.3

CVSS3.1

CVE-2025-11189 - CVE-2025-11189

The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

📅 Published: Oct. 10, 2025, 11:03 a.m. 🔄 Last Modified: Nov. 17, 2025, 2:38 p.m.

7.3

CVSS3.1

CVE-2025-11188 - CVE-2025-11188

The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.

📅 Published: Oct. 10, 2025, 11:02 a.m. 🔄 Last Modified: Nov. 14, 2025, 11:46 p.m.
Total resulsts: 349182
Page 3480 of 34,919
« previous page » next page
Filters