7.2

CVSS4.0

CVE-2025-59416 - The Scratch Channel forks can publish articles

The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since the API uses a POST request, it will make an article. This issue is fixed in v1.2.

πŸ“… Published: Sept. 17, 2025, 6:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-59414 - Nuxt Client-Side Path Traversal in Nuxt Island Payload Revival

Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vulnerability in Nuxt's Island payload revival mechanism allowed attackers to manipulate client-side requests to different endpoints within the same application domain when specific …

πŸ“… Published: Sept. 17, 2025, 6:39 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 6:47 p.m.

5.3

CVSS4.0

CVE-2025-10608 - Portabilis i-Educar enrollment-history access control

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit is now public and may be used.

πŸ“… Published: Sept. 17, 2025, 6:32 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 8:21 p.m.

5.3

CVSS4.0

CVE-2025-10607 - Portabilis i-Educar diarioApi information disclosure

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

πŸ“… Published: Sept. 17, 2025, 6:02 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 8:22 p.m.

5.3

CVSS4.0

CVE-2025-10606 - Portabilis i-Educar ConfiguracaoMovimentoGeral cross site scripting

A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remote exploitation of the attack is possible. The exploi…

πŸ“… Published: Sept. 17, 2025, 6:02 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 8:22 p.m.

5.5

CVSS4.0

CVE-2025-59342 - esm.sh writes arbitrary files via path traversal in `X-Zone-Id` header

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a …

πŸ“… Published: Sept. 17, 2025, 5:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-59341 - Local File Inclusion in esm.sh

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or othe…

πŸ“… Published: Sept. 17, 2025, 5:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-59339 - The Bastion ttyrec files are not signed after encryption by the osh-encrypt-rsync script

The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if …

πŸ“… Published: Sept. 17, 2025, 5:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.2

CVSS4.0

CVE-2025-58767 - REXML has a DoS condition when parsing malformed XML file

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulner…

πŸ“… Published: Sept. 17, 2025, 5:45 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 1:07 p.m.

9.1

CVSS3.1

CVE-2025-58766 - Dyad Vulnerable to Remote Code Execution via Top-level Navigation in Preview Window

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker con…

πŸ“… Published: Sept. 17, 2025, 5:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3804 of 34,919
Β« previous page Β» next page
Filters