5.1

CVSS4.0

CVE-2025-43741 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows …

πŸ“… Published: Aug. 20, 2025, 11:54 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 7:51 p.m.

6.9

CVSS4.0

CVE-2025-43742 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows …

πŸ“… Published: Aug. 20, 2025, 11:35 a.m. πŸ”„ Last Modified: Dec. 16, 2025, 3 p.m.

5.4

CVSS3.1

CVE-2025-8102 - Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_…

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated atta…

πŸ“… Published: Aug. 20, 2025, 11:26 a.m. πŸ”„ Last Modified: April 21, 2026, 3:30 a.m.

5.3

CVSS4.0

CVE-2025-9173 - Emlog Pro media.php unrestricted upload

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The file upload in include/service/media.php verifies the file extension based on a list defined in include/lib/opt…

πŸ“… Published: Aug. 20, 2025, 11:02 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 8:32 a.m.

4.3

CVSS3.1

CVE-2025-57734 -

In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

πŸ“… Published: Aug. 20, 2025, 9:14 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 3:29 p.m.

5.5

CVSS3.1

CVE-2025-57733 -

In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content

πŸ“… Published: Aug. 20, 2025, 9:14 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 3:23 p.m.

7.5

CVSS3.1

CVE-2025-57732 -

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

πŸ“… Published: Aug. 20, 2025, 9:14 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.7

CVSS3.1

CVE-2025-57731 -

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

πŸ“… Published: Aug. 20, 2025, 9:13 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 3:17 p.m.

5.2

CVSS3.1

CVE-2025-57730 -

In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature

πŸ“… Published: Aug. 20, 2025, 9:13 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:29 p.m.

6.5

CVSS3.1

CVE-2025-57729 -

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

πŸ“… Published: Aug. 20, 2025, 9:13 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 4201 of 34,919
Β« previous page Β» next page
Filters