6.5

CVSS3.1

CVE-2025-53494 - Stored XSS in TwoColConflict

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affects Mediawiki - TwoColConflict Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, fr…

📅 Published: July 2, 2025, 2:24 p.m. 🔄 Last Modified: July 2, 2025, 3:15 p.m.

8.9

CVSS4.0

CVE-2025-53006 - Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies…

📅 Published: July 2, 2025, 2:22 p.m. 🔄 Last Modified: July 2, 2025, 3:15 p.m.

8.7

CVSS4.0

CVE-2025-49588 - Linkwarden Local File Inclusion Vulnerability

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other u…

📅 Published: July 2, 2025, 2:05 p.m. 🔄 Last Modified: July 2, 2025, 3:15 p.m.

10

CVSS4.0

CVE-2025-34073 - stamparm/maltrail <=0.54 Remote Command Execution

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs due to unsafe handling of user-supplied input…

📅 Published: July 2, 2025, 1:46 p.m. 🔄 Last Modified: July 2, 2025, 8:30 p.m.

9.3

CVSS4.0

CVE-2025-34072 - Anthropic Slack MCP Server Data Exfiltration via Link Unfurling

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes untrusted data, it can be manipulated to generate messages containing attacker-crafted hyperlinks embeddin…

📅 Published: July 2, 2025, 1:46 p.m. 🔄 Last Modified: July 2, 2025, 8:29 p.m.

9.4

CVSS4.0

CVE-2025-34071 - GFI Kerio Control Unsigned System Image Upload Root Code Execution

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img files, which can be modified to include malicious scripts within…

📅 Published: July 2, 2025, 1:45 p.m. 🔄 Last Modified: July 3, 2025, 3:55 a.m.

10

CVSS4.0

CVE-2025-34070 - GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper au…

📅 Published: July 2, 2025, 1:44 p.m. 🔄 Last Modified: July 3, 2025, 3:55 a.m.

9.5

CVSS4.0

CVE-2025-34069 - GFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwarding

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP port 3128 can be used to forward unauthenticated requests to internal services such as GFIAgent, byp…

📅 Published: July 2, 2025, 1:44 p.m. 🔄 Last Modified: July 2, 2025, 8:26 p.m.

10

CVSS4.0

CVE-2025-34067 - Hikvision HikCentral (formerly "Integrated Security Management Platform") Remote Command Execution …

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an a…

📅 Published: July 2, 2025, 1:44 p.m. 🔄 Last Modified: July 2, 2025, 8:25 p.m.

8.7

CVSS4.0

CVE-2025-34057 - Ruijie NBR Router Administrative Credential Disclosure

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker c…

📅 Published: July 2, 2025, 1:43 p.m. 🔄 Last Modified: July 2, 2025, 8:24 p.m.
Total resulsts: 300122
Page 4 of 30,013
« previous page » next page
Filters