7.2

CVSS3.1

CVE-2025-9518 - atec Debug <= 1.2.22 - Authenticated (Administrator+) Arbitrary File Deletion

The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions up to, and including, 1.2.22. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete …

πŸ“… Published: Sept. 4, 2025, 4:23 a.m. πŸ”„ Last Modified: April 22, 2026, 10:30 p.m.

7.1

CVSS4.0

CVE-2025-43772 -

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service …

πŸ“… Published: Sept. 4, 2025, 1:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-58358 - Markdownify is vulnerable to command injection through pptx-to-markdown tool

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerability, caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject arbitrary system commands.…

πŸ“… Published: Sept. 4, 2025, 12:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9942 - CodeAstro Real Estate Management System submitproperty.php unrestricted upload

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Sept. 4, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:41 p.m.

5.3

CVSS4.0

CVE-2025-9941 - CodeAstro Real Estate Management System register.php unrestricted upload

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the argument uimage can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 4, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:58 p.m.

9.7

CVSS3.1

CVE-2025-58357 - 5ire Chat Message XSS Vulnerability Enables Remote Code Execution

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that enables content injection attacks through multiple vectors: malicious prompt injection pages, compromised MCP servers,…

πŸ“… Published: Sept. 4, 2025, 12:30 a.m. πŸ”„ Last Modified: Jan. 22, 2026, 8:09 p.m.

5.1

CVSS4.0

CVE-2025-9940 - CodeAstro Real Estate Management System feature.php cross site scripting

A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: Sept. 4, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 5:52 p.m.

5.1

CVSS4.0

CVE-2025-9939 - CodeAstro Real Estate Management System propertyview.php cross site scripting

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: Sept. 4, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 5:52 p.m.

7.8

CVSS3.1

CVE-2025-38724 - nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()

In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a co…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:39 p.m.

7.8

CVSS3.1

CVE-2025-38730 - io_uring/net: commit partial buffers on retry

In the Linux kernel, the following vulnerability has been resolved: io_uring/net: commit partial buffers on retry Ring provided buffers are potentially only valid within the single execution context in which they were acquired. io_uring deals with this and invalidates them on retry. But on the ne…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 9:50 p.m.
Total resulsts: 349182
Page 4021 of 34,919
Β« previous page Β» next page
Filters