6.9

CVSS4.0

CVE-2025-43756 -

<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.15, 2025.Q2.0 through 2025.Q2.2 and 2024.Q1.13 through 2024.Q1.19 allows a remote authenticated use…

πŸ“… Published: Aug. 21, 2025, 4:19 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:33 p.m.

9.8

CVSS3.1

CVE-2025-57754 - eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)

eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lea…

πŸ“… Published: Aug. 21, 2025, 4:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2025-57753 - vite-plugin-static-copy files not included in `src` are accessible with a crafted request

vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.

πŸ“… Published: Aug. 21, 2025, 4:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-9308 - yarnpkg Yarn request-manager.js setOptions redos

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects product…

πŸ“… Published: Aug. 21, 2025, 4:02 p.m. πŸ”„ Last Modified: Sept. 12, 2025, 12:58 p.m.

6.9

CVSS4.0

CVE-2025-9307 - PHPGurukul Online Course Registration session.php sql injection

A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Aug. 21, 2025, 4:02 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

6.9

CVSS4.0

CVE-2025-55744 - UnoPim vulnerable to CSRF on Product edit feature and creation of other types

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.

πŸ“… Published: Aug. 21, 2025, 3:51 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

7.3

CVSS4.0

CVE-2025-55743 - UnoPim vulnerable to remote code execution through Arbitrary File upload

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy …

πŸ“… Published: Aug. 21, 2025, 3:45 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

8

CVSS3.1

CVE-2025-55742 - UnoPim Stored XSS via SVG MIME/Sanitizer Bypass

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1.

πŸ“… Published: Aug. 21, 2025, 3:36 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

5.1

CVSS4.0

CVE-2025-9306 - SourceCodester Advanced School Management System addNotice cross site scripting

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting. It is possible to launch the attack remotely. Th…

πŸ“… Published: Aug. 21, 2025, 3:32 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 9:15 p.m.

5.2

CVSS4.0

CVE-2025-55297 - ESF-IDF BluFi Example Memory Overflow Vulnerability

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.

πŸ“… Published: Aug. 21, 2025, 3:05 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4:04 p.m.
Total resulsts: 349182
Page 4183 of 34,919
Β« previous page Β» next page
Filters