5.1

CVSS4.0

CVE-2025-40642 - Reflected Cross-Site Scripting (XSS) in WebWork

Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.

πŸ“… Published: Sept. 8, 2025, 11:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10091 - Jinher OA XML Type xml external entity reference

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible.…

πŸ“… Published: Sept. 8, 2025, 11:02 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 6:49 p.m.

9.2

CVSS4.0

CVE-2025-5993 - Path Traversal in ITCube CRM

ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.

πŸ“… Published: Sept. 8, 2025, 10:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2014-125128 -

'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.

πŸ“… Published: Sept. 8, 2025, 10:09 a.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:14 p.m.

6.1

CVSS3.1

CVE-2019-25225 - sanitize-html: sanitize-html cross site scripting

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be t…

πŸ“… Published: Sept. 8, 2025, 10:02 a.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:18 p.m.

6.9

CVSS4.0

CVE-2025-10090 - Jinher OA GetTreeDate.aspx sql injection

A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 8, 2025, 9:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 6:50 p.m.

6.5

CVSS3.1

CVE-2025-58782 - Apache Jackrabbit Core, Apache Jackrabbit JCR Commons: JNDI injection risk with JndiRepositoryFacto…

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrus…

πŸ“… Published: Sept. 8, 2025, 8:53 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 4:17 p.m.

5.1

CVSS4.0

CVE-2025-10088 - SourceCodester Time Tracker index.html cross site scripting

A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: Sept. 8, 2025, 7:02 a.m. πŸ”„ Last Modified: Sept. 8, 2025, 8:38 p.m.

7.5

CVSS3.1

CVE-2025-41664 - Improper Permission Handling Enables Unauthorized Access to Firmware and Certificates

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify firmware.

πŸ“… Published: Sept. 8, 2025, 6:39 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2025-41708 - Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.

πŸ“… Published: Sept. 8, 2025, 6:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3964 of 34,919
Β« previous page Β» next page
Filters