5.9

CVSS3.1

CVE-2025-8415 - Cryostat: authentication bypass if network policies are disabled

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-55482 -

Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 25, 2025, 1:32 a.m.

9.8

CVSS3.1

CVE-2025-55444 -

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 7:16 p.m.

6.9

CVSS4.0

CVE-2025-54364 -

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings contai…

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-50904 -

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 7:17 p.m.

9.8

CVSS3.1

CVE-2024-57154 -

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-55498 -

Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 25, 2025, 1:31 a.m.

4.8

CVSS3.1

CVE-2025-51990 -

XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can inject arbitrary JavaScript payloads into the HTTP …

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 1:51 p.m.

7.3

CVSS3.1

CVE-2025-55503 -

Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 2:30 p.m.

8.8

CVSS3.1

CVE-2025-51991 -

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is…

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 1:50 p.m.
Total resulsts: 349182
Page 4216 of 34,919
Β« previous page Β» next page
Filters