7.4

CVSS3.1

CVE-2025-59489 -

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be abl…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 6:12 p.m.

8.2

CVSS3.1

CVE-2025-56551 -

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 6:34 p.m.

7.5

CVSS3.1

CVE-2025-55972 -

A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to becom…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 1:12 p.m.

7.5

CVSS3.1

CVE-2025-11230 - Denial of service vulnerability in HAProxy mjson library

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 4:44 p.m.

6.1

CVSS3.1

CVE-2025-60445 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the dayrui/Fcms/Library/Upload.php component, allowing attackers to inject malicious JavaScript code that executes when th…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:22 p.m.

6.1

CVSS3.1

CVE-2025-60454 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the app\system\img\admin\img_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files contain…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 3:09 p.m.

6.1

CVSS3.1

CVE-2025-60451 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, specifically in the website settings module.…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 3:32 p.m.

6.1

CVSS3.1

CVE-2025-60448 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when th…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 8, 2025, 3:21 p.m.

5.9

CVSS3.1

CVE-2025-60447 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to pers…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 1:42 p.m.

6.5

CVSS3.1

CVE-2025-57423 -

A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Content, GroupName, PersonName, lastUpdate, pool, and title. Due to insufficient input sanitisation, an unauthenticated remote attacker could inject arbitrary SQL commands via a craf…

πŸ“… Published: Oct. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3587 of 34,919
Β« previous page Β» next page
Filters