4.8

CVSS4.0

CVE-2025-11570 -

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and P…

πŸ“… Published: Oct. 10, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-11569 -

This record was withdrawn by its CNA; further investigation revealed it was not a security issue.

πŸ“… Published: Oct. 10, 2025, 5 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 4:15 p.m.

8.4

CVSS4.0

CVE-2025-61871 -

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

πŸ“… Published: Oct. 10, 2025, 4:52 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11449 - Reflected Cross Site Scripting in ServiceNow AI Platform

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.Β Β Β  ServiceNow has addressed…

πŸ“… Published: Oct. 10, 2025, 1:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11450 - Reflected Cross Site Scripting in ServiceNow AI Platform

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this…

πŸ“… Published: Oct. 10, 2025, 1:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61152 -

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthori…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-60880 -

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in th…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 9:27 p.m.

9.9

CVSS3.1

CVE-2025-60306 -

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 4:25 p.m.

6.5

CVSS3.1

CVE-2025-61505 -

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could le…

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Feb. 3, 2026, 5:40 p.m.

8.8

CVSS3.1

CVE-2025-60305 -

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

πŸ“… Published: Oct. 10, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 5:41 p.m.
Total resulsts: 349182
Page 3486 of 34,919
Β« previous page Β» next page
Filters