4.8

CVSS4.0

CVE-2025-43791 -

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected i…

πŸ“… Published: Sept. 15, 2025, 6:08 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:15 p.m.

6.9

CVSS4.0

CVE-2025-59155 - hackmd-mcp server-side request forgery in HTTP transport mode

hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4.0 to before 1.5.0, hackmd-mcp contains a server-side request forgery (SSRF) vulnerability when the server is run in HTTP transport mode. Arbitrary hackmdApiUrl values supplied vi…

πŸ“… Published: Sept. 15, 2025, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-58177 - n8n stored cross-site scripting in LangChain Chat Trigger node initialMessages parameter

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages fi…

πŸ“… Published: Sept. 15, 2025, 4:49 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:34 p.m.

5.3

CVSS4.0

CVE-2025-58172 - drawnix debug logging cross-site scripting vulnerability

drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vulnerability exists in the debug logging functionality. User controlled content is inserted directly into the DOM via innerHTML without sanitization when the global function __draw…

πŸ“… Published: Sept. 15, 2025, 4:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10471 - ZKEACMS MediaController.cs Proxy server-side request forgery

A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipulation of the argument url results in server-side request forgery. It is possible to initiate the attack remotely. The exploit is now public and may b…

πŸ“… Published: Sept. 15, 2025, 4:32 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:34 p.m.

8.5

CVSS4.0

CVE-2025-10203 - Relative Path Traversal Vulnerability in Digilent WaveForms

Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent WaveForms 3.24.3 and…

πŸ“… Published: Sept. 15, 2025, 4:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-59328 - Apache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payloadΒ that, when processed, consumes an excessive amount of CPU resources during …

πŸ“… Published: Sept. 15, 2025, 4:26 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

2.3

CVSS4.0

CVE-2025-43792 -

Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the …

πŸ“… Published: Sept. 15, 2025, 4:19 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:28 p.m.

8.7

CVSS4.0

CVE-2025-58748 - Dataease H2 data source JDBC URL validation bypass leads to remote code execution

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that substitutes the Amazon …

πŸ“… Published: Sept. 15, 2025, 4:12 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 7:31 p.m.

7.8

CVSS3.1

CVE-2025-10491 - MongoDB Windows installation MSI may leave ACLs unset on custom installation directories

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and…

πŸ“… Published: Sept. 15, 2025, 4:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3854 of 34,919
Β« previous page Β» next page
Filters