5.1

CVSS4.0

CVE-2025-10591 - Portabilis i-Educar Editar Função educar_funcao_cad.php cross site scripting

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the component Editar Função Page. This manipulation of the argument abreviatura/tipoacao causes cross site scripting. The attack is possible to be carrie…

📅 Published: Sept. 17, 2025, 11:02 a.m. 🔄 Last Modified: Sept. 18, 2025, 8:23 p.m.

5.3

CVSS4.0

CVE-2025-10590 - Portabilis i-Educar educar_usuario_det.php cross site scripting

A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in cross site scripting. The attack can be executed remotely. The exploit has been rel…

📅 Published: Sept. 17, 2025, 11:02 a.m. 🔄 Last Modified: Sept. 18, 2025, 8:23 p.m.

9.3

CVSS4.0

CVE-2025-10156 - PickleScan Security Bypass via Bad CRC in ZIP Archive

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scan…

📅 Published: Sept. 17, 2025, 10:41 a.m. 🔄 Last Modified: Oct. 2, 2025, 7:04 p.m.

9.3

CVSS4.0

CVE-2025-10155 - PickleScan Security Bypass Using Misleading File Extension

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly c…

📅 Published: Sept. 17, 2025, 9:38 a.m. 🔄 Last Modified: Oct. 2, 2025, 7:07 p.m.

4.7

CVSS3.1

CVE-2025-0420 - XSS in Mikrogrup's Paraşüt

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Paraşüt allows Cross-Site Scripting (XSS).This issue affects Paraşüt: from 0.0.0.65efa44e through 20250204.

📅 Published: Sept. 17, 2025, 9:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-59458 -

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation

📅 Published: Sept. 17, 2025, 9:04 a.m. 🔄 Last Modified: Jan. 20, 2026, 5:31 p.m.

7.7

CVSS3.1

CVE-2025-59457 -

In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

📅 Published: Sept. 17, 2025, 9:04 a.m. 🔄 Last Modified: Sept. 22, 2025, 5:07 p.m.

5.5

CVSS3.1

CVE-2025-59456 -

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

📅 Published: Sept. 17, 2025, 9:04 a.m. 🔄 Last Modified: Sept. 22, 2025, 5:07 p.m.

4.2

CVSS3.1

CVE-2025-59455 -

In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

📅 Published: Sept. 17, 2025, 9:04 a.m. 🔄 Last Modified: Sept. 22, 2025, 5:07 p.m.

4.7

CVSS3.1

CVE-2025-0419 - XSS in Mikrogrup's Zirve Nova

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS).This issue affects Zirve Nova: from 235 through 20250131.

📅 Published: Sept. 17, 2025, 8:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3809 of 34,919
« previous page » next page
Filters