4.8

CVSS4.0

CVE-2025-11019 - Total.js CMS Files Menu cross site scripting

A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Sept. 26, 2025, 2:32 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:01 p.m.

3.7

CVSS3.1

CVE-2025-36326 - IBM Controller information disclosure

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.

πŸ“… Published: Sept. 26, 2025, 2:20 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 7:14 p.m.

7.5

CVSS3.1

CVE-2025-36274 - IBM Aspera HTTP Gateway information disclosure

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.

πŸ“… Published: Sept. 26, 2025, 2:14 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 10:12 p.m.

6.1

CVSS3.1

CVE-2025-6396 - XSS in Webbeyaz's web site

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz Website Design Website Software allows Cross-Site Scripting (XSS).This issue affects Website Software: through 2025.07.14.

πŸ“… Published: Sept. 26, 2025, 2:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-11018 - Four-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversal

A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the argument fileName can lead to path traversal. It is possible to launch th…

πŸ“… Published: Sept. 26, 2025, 2:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 8:24 p.m.

4.8

CVSS4.0

CVE-2025-11017 - OGRECave Ogre OgreLogManager.cpp stream null pointer dereference

A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::stream of the file /ogre/OgreMain/src/OgreLogManager.cpp. Performing manipulation of the argument mDefaultLog results in null pointer dereference. The attack must be initiated from a l…

πŸ“… Published: Sept. 26, 2025, 2:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 8:28 p.m.

5.3

CVSS4.0

CVE-2025-11016 - kalcaddle kodbox index.class.php fileOut path traversal

A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path leads to path traversal. The attack may be performed from remote. The exploit has be…

πŸ“… Published: Sept. 26, 2025, 1:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-11015 - OGRECave Ogre OgreSTBICodec.cpp encode mismatched memory management routines

A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes mismatched memory management routines. The attack is restricted to local execution. The exploit has been …

πŸ“… Published: Sept. 26, 2025, 1:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-11025 - Information Disclosure in Vimeosoft Information Technologies' Vimesoft Corporate Messaging Platform

Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.

πŸ“… Published: Sept. 26, 2025, 12:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-9267 -

In Seagate Toolkit on Windows aΒ vulnerability exists in the Toolkit Installer prior toΒ versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their origin or integrity. This behavior can be exploited by placing a malicious DLL in the same directory as…

πŸ“… Published: Sept. 26, 2025, 12:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3662 of 34,919
Β« previous page Β» next page
Filters