2.1

CVSS4.0

CVE-2025-54812 - Apache Log4cxx: Improper HTML escaping in HTMLLayout

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could theoretically inject HTML or Javascript in order t…

πŸ“… Published: Aug. 22, 2025, 6:46 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.3

CVSS4.0

CVE-2025-54813 - Apache Log4cxx: Improper escaping with JSONLayout

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON messa…

πŸ“… Published: Aug. 22, 2025, 6:45 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-43762 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the form…

πŸ“… Published: Aug. 22, 2025, 6:43 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:10 p.m.

7.6

CVSS3.1

CVE-2024-48988 - Apache StreamPark: SQL injection vulnerability

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Ma…

πŸ“… Published: Aug. 22, 2025, 6:24 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-43758 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploa…

πŸ“… Published: Aug. 22, 2025, 6:18 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:53 p.m.

5.3

CVSS4.0

CVE-2025-43760 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92 allows …

πŸ“… Published: Aug. 22, 2025, 5:34 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:54 p.m.

8.8

CVSS3.1

CVE-2025-57800 - Audiobookshelf vulnerable to OIDC token exfiltration and account takeover

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary callback in a cookie, wh…

πŸ“… Published: Aug. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 9:37 p.m.

5.3

CVSS3.1

CVE-2025-57770 - ZITADEL user enumeration vulnerability in login UI

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue in the login interface. The login UI includes a security fe…

πŸ“… Published: Aug. 22, 2025, 4:50 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 7:12 p.m.

8.1

CVSS3.1

CVE-2025-57771 - Roo-Code potential remote code execution via auto-execute command parsing flaw

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitution and single ampersand characters in the command parsing logic for auto-execute commands. If a user has enabled auto-approved execution f…

πŸ“… Published: Aug. 22, 2025, 4:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.5

CVSS4.0

CVE-2025-55745 - UnoPim Quick Export feature is vulnerable to CSV injection

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious content into exported …

πŸ“… Published: Aug. 22, 2025, 4:14 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.
Total resulsts: 349182
Page 4161 of 34,919
Β« previous page Β» next page
Filters