8.8

CVSS4.0

CVE-2025-59330 - [email protected] contains malware after npm account takeover

error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect c…

📅 Published: Sept. 15, 2025, 7:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59162 - [email protected] contains malware after npm account takeover

color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken over after a phishing attack. Version 3.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attemp…

📅 Published: Sept. 15, 2025, 7:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59142 - [email protected] contains malware after npm account takeover

color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to re…

📅 Published: Sept. 15, 2025, 7:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59144 - [email protected] contains malware after npm account takeover

debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transa…

📅 Published: Sept. 15, 2025, 7:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59143 - [email protected] contains malware after npm account takeover

color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redire…

📅 Published: Sept. 15, 2025, 7:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59141 - [email protected] contains malware after npm account takeover

simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocur…

📅 Published: Sept. 15, 2025, 7:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-59140 - [email protected] contains malware after npm account takeover

backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurr…

📅 Published: Sept. 15, 2025, 7:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-43800 -

Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a r…

📅 Published: Sept. 15, 2025, 7:07 p.m. 🔄 Last Modified: Dec. 16, 2025, 4:12 p.m.

5.3

CVSS4.0

CVE-2025-10473 - yangzongzhuan RuoYi Blacklist SqlUtil.java filterKeyword sql injection

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the component Blacklist Handler. The manipulation results in sql injection. The attack may be launched remotely. The exploit has be…

📅 Published: Sept. 15, 2025, 7:02 p.m. 🔄 Last Modified: Sept. 17, 2025, 5 p.m.

6.9

CVSS4.0

CVE-2025-10472 - harry0703 MoneyPrinterTurbo URL video.py stream_video path traversal

A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path leads to path traversal. The attack can be ini…

📅 Published: Sept. 15, 2025, 6:32 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:11 p.m.
Total resulsts: 349182
Page 3853 of 34,919
« previous page » next page
Filters