4.3

CVSS3.1

CVE-2025-59426 - lobe-chat has an Open Redirect

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a r…

📅 Published: Sept. 25, 2025, 2 p.m. 🔄 Last Modified: Oct. 8, 2025, 4:11 p.m.

8.6

CVSS3.1

CVE-2025-59839 - Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data …

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for …

📅 Published: Sept. 25, 2025, 1:56 p.m. 🔄 Last Modified: Oct. 14, 2025, 8:02 p.m.

8.7

CVSS4.0

CVE-2025-27261 - Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command V…

Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.

📅 Published: Sept. 25, 2025, 1:47 p.m. 🔄 Last Modified: Oct. 2, 2025, 5:57 p.m.

9.8

CVSS3.1

CVE-2025-59834 - Command Injection in adb-mcp MCP Server

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementatio…

📅 Published: Sept. 25, 2025, 1:41 p.m. 🔄 Last Modified: Oct. 14, 2025, 8:05 p.m.

8.7

CVSS4.0

CVE-2025-59831 - `git-comiters` Command Injection vulnerability

git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary exported API: gitCommiters(options, callback) which allows spe…

📅 Published: Sept. 25, 2025, 1:34 p.m. 🔄 Last Modified: Oct. 16, 2025, 3:45 p.m.

8.9

CVSS3.1

CVE-2025-10467 - Stored XSS in Proliz Software's OBS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS.This issue affects OBS (Student Affairs Information System): before v25.04…

📅 Published: Sept. 25, 2025, 1:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2025-59422 - Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Others

Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same workspace to read chat messages of other users. A regular user is …

📅 Published: Sept. 25, 2025, 1:19 p.m. 🔄 Last Modified: Oct. 14, 2025, 2:10 p.m.

3.9

CVSS3.1

CVE-2025-5494 - Privilege Escalation

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

📅 Published: Sept. 25, 2025, 1:11 p.m. 🔄 Last Modified: Oct. 22, 2025, 7:42 p.m.

6.9

CVSS4.0

CVE-2025-10947 - Sistemas Pleno Gestão de Locação CPF validarCpf authorization

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pessoa/validarCpf of the component CPF Handler. Executing a manipulation of the argument pes_cpf can lead to authorization bypass. The attack can be exe…

📅 Published: Sept. 25, 2025, 1:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-10946 - nuz007 smsboom dy.php cross site scripting

A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is an unknown function of the file dy.php. Performing manipulation of the argument hm results in cross site scripting. Remote exploitation of the attack is possible. This product foll…

📅 Published: Sept. 25, 2025, 1:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3685 of 34,919
« previous page » next page
Filters