8.5

CVSS4.0

CVE-2025-55201 - Copier safe template has arbitrary filesystem read/write access

Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write arbitrary files because Copier exposes a few pathlib.Path objects in the Jinja context which have unconstrained I/O methods. This effectively renders the security model w.r.t. fiโ€ฆ

๐Ÿ“… Published: Aug. 18, 2025, 4:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-54117 - NamelessMC allows Stored Cross-Site Scripting (XSS) in dashboard text editor

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed โ€ฆ

๐Ÿ“… Published: Aug. 18, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 9:23 p.m.

7.2

CVSS3.1

CVE-2025-54421 - NamelessMC allows Stored Cross Site Scripting (XSS) in SEO component

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixโ€ฆ

๐Ÿ“… Published: Aug. 18, 2025, 4:01 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 9:23 p.m.

5.3

CVSS3.1

CVE-2025-54118 - NamelessMC allows sensitive information disclosure in member list component

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fiโ€ฆ

๐Ÿ“… Published: Aug. 18, 2025, 3:59 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 9:23 p.m.

6.2

CVSS3.1

CVE-2025-33100 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

๐Ÿ“… Published: Aug. 18, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2025-33090 - IBM Concert Software denial of service

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

๐Ÿ“… Published: Aug. 18, 2025, 2:01 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 7:25 p.m.

5.4

CVSS3.1

CVE-2025-27909 - IBM Concert Software cross-origin resource sharing

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.

๐Ÿ“… Published: Aug. 18, 2025, 2 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 8:56 p.m.

5.9

CVSS3.1

CVE-2025-1759 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

๐Ÿ“… Published: Aug. 18, 2025, 1:58 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 8:09 p.m.

3.7

CVSS3.1

CVE-2024-49827 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.

๐Ÿ“… Published: Aug. 18, 2025, 1:43 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-36120 - IBM Storage Virtualize privilege escalation

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.

๐Ÿ“… Published: Aug. 18, 2025, 1:39 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 4240 of 34,919
ยซ previous page ยป next page
Filters