5.1
CVE-2025-43741 -
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows β¦
6.9
CVE-2025-43742 -
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows β¦
5.4
CVE-2025-8102 - Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_β¦
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attaβ¦
5.3
CVE-2025-9173 - Emlog Pro media.php unrestricted upload
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The file upload in include/service/media.php verifies the file extension based on a list defined in include/lib/optβ¦
4.3
CVE-2025-57734 -
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
5.5
CVE-2025-57733 -
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
7.5
CVE-2025-57732 -
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
8.7
CVE-2025-57731 -
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
5.2
CVE-2025-57730 -
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
6.5
CVE-2025-57729 -
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start