6.9
CVE-2025-11030 - Tutorials-Website Employee Management System HTTP Request all-applied-leave.php improper authorizatโฆ
A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837a60. Impacted is an unknown function of the file /admin/all-applied-leave.php of the component HTTP Request Handler. The manipulation results in improper authorization. The attackโฆ
5.3
CVE-2025-11029 - givanz Vvveb cross-site request forgery
A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. Once again the projectโฆ
0.0
CVE-2025-61596 -
This is a fork and is not in the Rust registry.
0.0
CVE-2025-61585 -
Further research determined the issue is not an independent vulnerability as it originates from Apache Felix.
7.7
CVE-2025-59844 - Argument injection vulnerability in SonarQube Scan Action
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runneโฆ
6.9
CVE-2025-59843 - FlagForgeCTF Exposes User Emails via Public /api/user/[username] API
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public โฆ
6.9
CVE-2025-11028 - givanz Vvveb Image information disclosure
A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.โฆ
4.8
CVE-2025-11027 - givanz Vvveb SVG File cross site scripting
A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of the component SVG File Handler. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. Once againโฆ
2.1
CVE-2025-59842 - JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the noopener attribuโฆ
5.1
CVE-2025-11026 - givanz Vvveb Configuration File information disclosure
A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and maโฆ