8.8

CVSS3.1

CVE-2025-52360 -

A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary JavaScript in the browser context when the user in…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 26, 2025, 11:22 a.m.

6.1

CVSS3.1

CVE-2025-51411 -

A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email parameter in the /postquerypublic endpoint. The application fails to properly sanitize user input before reflecting it in the HTML response. This allows unauthenticated attackers to injec…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

6.5

CVSS3.1

CVE-2025-45939 -

Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

6.1

CVSS3.1

CVE-2025-45892 -

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 2:14 p.m.

9.8

CVSS3.1

CVE-2025-45777 -

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

6.5

CVSS3.1

CVE-2025-44608 -

CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 25, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-38452 - net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe()

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 2:14 p.m.

7.0

CVSS3.1

CVE-2025-38415 - Squashfs: check return result of sb_min_blocksize

In the Linux kernel, the following vulnerability has been resolved: Squashfs: check return result of sb_min_blocksize Syzkaller reports an "UBSAN: shift-out-of-bounds in squashfs_bio_read" bug. Syzkaller forks multiple processes which after mounting the Squashfs filesystem, issues an ioctl("/dev…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 28, 2025, 4:21 a.m.

5.5

CVSS3.1

CVE-2025-38405 - nvmet: fix memory leak of bio integrity

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak of bio integrity If nvmet receives commands with metadata there is a continuous memory leak of kmalloc-128 slab or more precisely bio->bi_integrity. Since commit bf4c89fc8797 ("block: don't call bio_uninit…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 28, 2025, 12:45 p.m.

7.0

CVSS3.1

CVE-2025-38375 - virtio-net: ensure the received length does not exceed allocated size

In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to a…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: July 28, 2025, 4:20 a.m.
Total resulsts: 303541
Page 37 of 30,355
Β« previous page Β» next page
Filters