8.6

CVSS3.1

CVE-2025-53370 - Citizen stored XSS vulnerability through short descriptions

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension are inserted as raw HTML by the Citizen skin, allowing any user to insert arbitrary HTML into the DOM by editing a page. …

πŸ“… Published: July 3, 2025, 7:45 p.m. πŸ”„ Last Modified: July 3, 2025, 8:15 p.m.

8.6

CVSS3.1

CVE-2025-53368 - Citizen is vulnerable to stored XSS attack in the legacy search bar

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-…

πŸ“… Published: July 3, 2025, 7:34 p.m. πŸ”„ Last Modified: July 3, 2025, 8:15 p.m.

9.1

CVSS3.1

CVE-2025-23968 - WordPress AiBud WP plugin <= 1.8.5 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in WPCenter AiBud WP allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through 1.8.5.

πŸ“… Published: July 3, 2025, 6:49 p.m. πŸ”„ Last Modified: July 3, 2025, 7:15 p.m.

6.3

CVSS4.0

CVE-2025-6071 - Hard Coded Key used for AES encryption

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

πŸ“… Published: July 3, 2025, 4:56 p.m. πŸ”„ Last Modified: July 3, 2025, 5:54 p.m.

8.2

CVSS4.0

CVE-2025-6072 - Stack Buffer Overflow in MQTTCore

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.Th…

πŸ“… Published: July 3, 2025, 4:53 p.m. πŸ”„ Last Modified: July 3, 2025, 5:55 p.m.

8.2

CVSS4.0

CVE-2025-6073 - Stack Buffer Overflow in MQTTCore

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer …

πŸ“… Published: July 3, 2025, 4:49 p.m. πŸ”„ Last Modified: July 3, 2025, 6:15 p.m.

6.3

CVSS4.0

CVE-2025-6074 - Authentication Bypass to the MQTT configuration Web Interface

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration dat…

πŸ“… Published: July 3, 2025, 4:46 p.m. πŸ”„ Last Modified: July 3, 2025, 6:19 p.m.

4.1

CVSS4.0

CVE-2025-49846 - wire-ios accidentally logs message contents

wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created and managed by the application itself were not affected, esp…

πŸ“… Published: July 3, 2025, 4:41 p.m. πŸ”„ Last Modified: July 3, 2025, 7:23 p.m.

4.2

CVSS3.1

CVE-2025-48939 - tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clob…

πŸ“… Published: July 3, 2025, 4:26 p.m. πŸ”„ Last Modified: July 3, 2025, 7:15 p.m.

8.8

CVSS3.1

CVE-2025-6926 - Security Authentication Bypass in CentralAuth

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

πŸ“… Published: July 3, 2025, 4:23 p.m. πŸ”„ Last Modified: July 3, 2025, 6:15 p.m.
Total resulsts: 300289
Page 4 of 30,029
Β« previous page Β» next page
Filters