8.4

CVSS3.1

CVE-2025-7388 - Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property…

📅 Published: Sept. 4, 2025, 1:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-7385 - SQL Injection in GOV CMS

Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.

📅 Published: Sept. 4, 2025, 12:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-41063 - Reflected Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.

📅 Published: Sept. 4, 2025, 11:16 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

4.8

CVSS4.0

CVE-2025-41062 - Reflected Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

📅 Published: Sept. 4, 2025, 11:16 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41061 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/uploadify.

📅 Published: Sept. 4, 2025, 11:15 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41060 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tree.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41059 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tablesorter.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41058 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/row_manager.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:51 p.m.

5.1

CVSS4.0

CVE-2025-41057 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/rich_text_editor.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:51 p.m.

5.1

CVSS4.0

CVE-2025-41056 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/hysontable.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:51 p.m.
Total resulsts: 349182
Page 4014 of 34,919
« previous page » next page
Filters