6.1

CVSS3.1

CVE-2025-9034 - Wp Edit Password Protected < 1.3.5 - Open Redirect

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

πŸ“… Published: Sept. 11, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10247 - JEPaaS Filter doFilterInternal access control

A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Th…

πŸ“… Published: Sept. 11, 2025, 5:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-9059 - Elevation of Privileges Vulnerability in IT Management Suite

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

πŸ“… Published: Sept. 11, 2025, 5:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-10246 - lokibhardwaj PHP-Code-For-Unlimited-File-Upload f.php cross site scripting

A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The expl…

πŸ“… Published: Sept. 11, 2025, 5:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-9910 -

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer u…

πŸ“… Published: Sept. 11, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-9776 - CatFolders – Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL I…

The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

πŸ“… Published: Sept. 11, 2025, 4:26 a.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

4.8

CVSS4.0

CVE-2025-10245 - Display PainΓ©is TGA Galeria rename path traversal

A security flaw has been discovered in Display PainΓ©is TGA up to 7.1.41. Affected by this issue is some unknown functionality of the file /gallery/rename of the component Galeria Page. The manipulation of the argument current_folder results in path traversal. The exploit has been released to the pu…

πŸ“… Published: Sept. 11, 2025, 1:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10236 - binary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversal

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} leads to path traversal. The attack may be launche…

πŸ“… Published: Sept. 11, 2025, 1:02 a.m. πŸ”„ Last Modified: Oct. 31, 2025, 2:39 p.m.

3.1

CVSS3.1

CVE-2025-6088 - Improper Authorization in danny-avila/librechat

In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Although UUIDv4 conversation IDs are generated server-side and are difficult to brute force, they c…

πŸ“… Published: Sept. 11, 2025, 12:43 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 4 p.m.

4.8

CVSS4.0

CVE-2025-10235 - Scada-LTS Reports reports.shtm cross site scripting

A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of the argument Colour causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may …

πŸ“… Published: Sept. 11, 2025, 12:32 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:18 p.m.
Total resulsts: 349182
Page 3908 of 34,919
Β« previous page Β» next page
Filters