7.3

CVSS3.1

CVE-2025-55888 -

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution iโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 7:51 p.m.

7.8

CVSS3.1

CVE-2025-51006 -

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. Byโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 7:58 p.m.

4.3

CVSS3.1

CVE-2025-59801 -

In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-59799 - Artifex Ghostscript: From CVEorg collector

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 6:17 p.m.

4.3

CVSS3.1

CVE-2025-59798 - Artifex Ghostscript: From CVEorg collector

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 6:17 p.m.

5.8

CVSS3.1

CVE-2025-59797 -

Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URLs for eversports, the user-management page, and the plane page.

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-55887 -

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that โ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 7:51 p.m.

5.4

CVSS3.1

CVE-2025-57205 -

iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:43 p.m.

9.8

CVSS3.1

CVE-2025-56074 -

A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2025, 7:14 p.m.

4.8

CVSS3.1

CVE-2025-57203 -

MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feature available to authenticated admin users. The vulnerability resides in the prompt parameter submitted to the /dashboard/user/generator/generate-stream endpoint via a multipart/fโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:49 p.m.
Total resulsts: 349182
Page 3759 of 34,919
ยซ previous page ยป next page
Filters