5.3

CVSS4.0

CVE-2025-11049 - Portabilis i-Educar unificacao-aluno improper authorization

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. Performing manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.

๐Ÿ“… Published: Sept. 27, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 6:31 p.m.

4.3

CVSS3.1

CVE-2025-10498 - Ninja Forms โ€“ The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery tโ€ฆ

The Ninja Forms โ€“ The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackeโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 2:25 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3 a.m.

4.3

CVSS3.1

CVE-2025-10499 - Ninja Forms โ€“ The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery tโ€ฆ

The Ninja Forms โ€“ The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticatโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 2:25 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3 a.m.

6.4

CVSS3.1

CVE-2025-8440 - Team Members <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 1:46 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:30 p.m.

6.1

CVSS3.1

CVE-2025-36239 - IBM Storage TS4500 Library cross-site scripting

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted seโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 1:16 a.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 10:09 p.m.

6.5

CVSS3.1

CVE-2024-43192 - IBM Storage TS4500 Library cross-site request forgery

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

๐Ÿ“… Published: Sept. 27, 2025, 1:14 a.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 10:10 p.m.

8.1

CVSS3.1

CVE-2025-59945 - SysReptor Susceptible to Privilege Escalation by Authenticated Users

SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not membโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 1:01 a.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 9:18 p.m.

8.6

CVSS3.1

CVE-2025-59932 - FlagForgeCTF Unauthenticated Resource Modification/Deletion

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 12:51 a.m. ๐Ÿ”„ Last Modified: Oct. 8, 2025, 4:56 p.m.

8.8

CVSS3.1

CVE-2025-59939 - WeGIA vulnerable to SQL Injection into method `excluir` of the `ProdutoControle` class in the paraโ€ฆ

WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the following parameters: nomeClasse=ProdutoControle&metodo=excluir&id_produto=[malicious command]. It is necessary to apply prepared statements โ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 3:05 p.m.

6.5

CVSS3.1

CVE-2025-59938 - Heap buffer overflow in wazuh-analysisd

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from 3.8.0 to before 4.11.0, wazuh-analysisd is vulnerable to a heap buffer overflow when parsing XML elements from Windows EventChannel messages. This issue has been patched in versioโ€ฆ

๐Ÿ“… Published: Sept. 27, 2025, 12:27 a.m. ๐Ÿ”„ Last Modified: Oct. 16, 2025, 5:33 p.m.
Total resulsts: 349182
Page 3658 of 34,919
ยซ previous page ยป next page
Filters