5.1

CVSS4.0

CVE-2025-9657 - O2OA Personal Profile script cross site scripting

A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_center/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site scripting. The attack may be launched remo…

📅 Published: Aug. 29, 2025, 3:32 p.m. 🔄 Last Modified: Sept. 16, 2025, 4:32 p.m.

5.3

CVSS4.0

CVE-2025-9656 - PHPGurukul Directory Management System add-directory.php cross site scripting

A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

📅 Published: Aug. 29, 2025, 3:32 p.m. 🔄 Last Modified: Sept. 18, 2025, 2:39 p.m.

5.3

CVSS3.1

CVE-2025-54877 - Tuleap's special and always there fields permissions are not verified in cross-tracker search

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special an…

📅 Published: Aug. 29, 2025, 3:07 p.m. 🔄 Last Modified: Sept. 3, 2025, 4:09 p.m.

5.1

CVSS4.0

CVE-2025-9655 - O2OA Personal Profile person cross site scripting

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be launched remo…

📅 Published: Aug. 29, 2025, 3:02 p.m. 🔄 Last Modified: Sept. 16, 2025, 4:34 p.m.

5.3

CVSS4.0

CVE-2025-9654 - AiondaDotCom mcp-ssh server-simple.mjs command injection

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing manipulation results in command injection. The attack can be initiated remotely. Upgrading to version 1.0.4 and 1.1.0 can resolve t…

📅 Published: Aug. 29, 2025, 3:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2025-55304 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time…

📅 Published: Aug. 29, 2025, 3 p.m. 🔄 Last Modified: Sept. 2, 2025, 1:21 p.m.

5.3

CVSS3.1

CVE-2025-11065 - Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs…

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-crit…

📅 Published: Aug. 29, 2025, 2:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2025-54080 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An at…

📅 Published: Aug. 29, 2025, 2:50 p.m. 🔄 Last Modified: Sept. 2, 2025, 1:29 p.m.

5.1

CVSS4.0

CVE-2025-9653 - Portabilis i-Educar Cadastrar projeto educar_projeto_cad.php cross site scripting

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_projeto_cad.php of the component Cadastrar projeto Page. Such manipulation of the argument nome/observacao leads to cross site scripting. It is p…

📅 Published: Aug. 29, 2025, 2:32 p.m. 🔄 Last Modified: Sept. 4, 2025, 6:16 p.m.

5.1

CVSS4.0

CVE-2025-9652 - Portabilis i-Educar Cadastrar tipo de transferência educar_transferencia_tipo_cad.php cross site sc…

A vulnerability was determined in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /intranet/educar_transferencia_tipo_cad.php of the component Cadastrar tipo de transferência Page. This manipulation of the argument nm_tipo/desc_tipo causes cross site scripting. It is pos…

📅 Published: Aug. 29, 2025, 2:32 p.m. 🔄 Last Modified: Sept. 4, 2025, 6:17 p.m.
Total resulsts: 349182
Page 4087 of 34,919
« previous page » next page
Filters