4.6

CVSS4.0

CVE-2025-54089 - Cross-site Scripting vulnerability in Secure Access prior to 14.10

CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administratorโ€™s access to the console. The attack complexity is low; there are no attack requirements. Privileges requirโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:15 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2025, 6:21 p.m.

9.4

CVSS4.0

CVE-2025-61605 - WeGIA: SQL Injection (Blind Time-Based) Vulnerability in /pet/profile_pet.php Endpoint

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified in the /pet/profile_pet.php endpoint, specifically in the id_pet parameter. This vulnerability allows attackers to execute arbitrary SQLโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:13 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:42 p.m.

5.5

CVSS4.0

CVE-2025-54088 - Open Redirect in Secure Access prior to 14.10

CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in โ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:10 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2025, 6:22 p.m.

7.1

CVSS4.0

CVE-2025-61604 - WeGIA: Cross-Site Request Forgery (CSRF) Vulnerability in `control.php` Endpoint

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The delete operation for the Almoxarifado entity is exposed via HTTP GET without CSRF protection, allowing a third-party site to trigger โ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:09 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:42 p.m.

1.8

CVSS4.0

CVE-2025-54087 - Server-side request forgery in Secure Access

CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and useโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:05 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2025, 6:22 p.m.

8.6

CVSS3.1

CVE-2025-10653 - Raise3D Pro2 Series 3D Printers Authentication Bypass Using an Alternate Path or Channel

An unauthenticated debug port may allow access to the device file system.

๐Ÿ“… Published: Oct. 2, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-54086 - Excess Permissions in Warehouse

CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required โ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2025, 6:23 p.m.

9.4

CVSS4.0

CVE-2025-61603 - WeGIA: SQL Injection (Blind Time-Based) Vulnerability in API `descricao` Parameter

WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromisiโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 7:53 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:43 p.m.

8.8

CVSS4.0

CVE-2025-61595 - MANTRA tx gas limit is not enforced in send hooks

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 7:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-59835 - LangBot has a cross-directory file upload vulnerability, which could lead to system takeover

LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory of files on the serโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 6:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3589 of 34,919
ยซ previous page ยป next page
Filters