8.7

CVSS4.0

CVE-2025-59536 - Claude Code's startup trust dialog could lead to Command Execution attack

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a…

📅 Published: Oct. 3, 2025, 6:34 a.m. 🔄 Last Modified: Oct. 23, 2025, 12:46 p.m.

5.1

CVSS4.0

CVE-2025-61599 - Emlog is Vulnerable to Stored Cross-Site Scripting (XSS) in "Twitter" Feature via Markdown Input

Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An authenticated user with privileges to post a "Twitter" message can inject arbitrary JavaScript code. The malicious script is stored on …

📅 Published: Oct. 3, 2025, 6:27 a.m. 🔄 Last Modified: Oct. 8, 2025, 3:26 p.m.

7.6

CVSS3.1

CVE-2025-61597 - Emlog Pro is vulnerable to stored XSS attack through HTML template injection

Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated admin context will exec…

📅 Published: Oct. 3, 2025, 6:16 a.m. 🔄 Last Modified: Oct. 20, 2025, 5:50 p.m.

6.8

CVSS4.0

CVE-2025-59300 - File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

📅 Published: Oct. 3, 2025, 2:24 a.m. 🔄 Last Modified: Oct. 8, 2025, 4:06 p.m.

6.8

CVSS4.0

CVE-2025-59299 - File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

📅 Published: Oct. 3, 2025, 2:24 a.m. 🔄 Last Modified: Oct. 8, 2025, 4:06 p.m.

6.8

CVSS4.0

CVE-2025-59298 - File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

📅 Published: Oct. 3, 2025, 2:22 a.m. 🔄 Last Modified: Oct. 8, 2025, 4:06 p.m.

6.8

CVSS4.0

CVE-2025-59297 - File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

📅 Published: Oct. 3, 2025, 2:21 a.m. 🔄 Last Modified: Oct. 8, 2025, 4:07 p.m.

6.4

CVSS3.1

CVE-2025-11241 - Yoast SEO Premium 25.7-25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows…

📅 Published: Oct. 3, 2025, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-60452 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to upload malicious SVG …

📅 Published: Oct. 3, 2025, midnight 🔄 Last Modified: Oct. 7, 2025, 3:27 p.m.

6.1

CVSS3.1

CVE-2025-60453 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload malicious SVG files contain…

📅 Published: Oct. 3, 2025, midnight 🔄 Last Modified: Oct. 7, 2025, 3:21 p.m.
Total resulsts: 349182
Page 3586 of 34,919
« previous page » next page
Filters