6.5

CVSS3.1

CVE-2025-53820 - WeGIA vulnerable to Cross-Site Scripting (XSS) Reflected via endpoint 'index.php' parameter 'erro'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `index.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject mal…

πŸ“… Published: July 14, 2025, 8:47 p.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

7.9

CVSS3.1

CVE-2025-53819 - Nix's privilege dropping to build user broke for macOS

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

πŸ“… Published: July 14, 2025, 8:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-53818 - github-kanban-mcp-server Command Injection vulnerability

GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Serv…

πŸ“… Published: July 14, 2025, 8:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.7

CVSS4.0

CVE-2025-53643 - AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trail…

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the u…

πŸ“… Published: July 14, 2025, 8:17 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:40 p.m.

5.3

CVSS4.0

CVE-2025-53640 - Indico vulnerable to user enumeration via API endpoint

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could be misused to dump basic user details (such…

πŸ“… Published: July 14, 2025, 8:14 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 6:55 p.m.

5.1

CVSS4.0

CVE-2025-53639 - Metersphere has SQL Injection Vulnerability in Sorting Field

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply crafted input to inject and execute arbitrary SQL statements through the sorting functionality. This…

πŸ“… Published: July 14, 2025, 8:04 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 8:47 p.m.

8.1

CVSS4.0

CVE-2025-53623 - Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class

The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code execution vulnerability in the `CsvEnumerator` class. This vulnerability can be exploited by an attacker to execute arbitrary commands on the system wher…

πŸ“… Published: July 14, 2025, 7:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2025-53101 - ImageMagick has Stack Buffer Overflow in image.c

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to g…

πŸ“… Published: July 14, 2025, 7:51 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

3.7

CVSS3.1

CVE-2025-53019 - ImageMagick has Memory Leak in magick stream

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 a…

πŸ“… Published: July 14, 2025, 7:42 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

7.5

CVSS3.1

CVE-2025-53015 - ImageMagick has XMP profile write that triggers hang due to unbounded loop

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.

πŸ“… Published: July 14, 2025, 7:31 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:06 p.m.
Total resulsts: 345362
Page 4267 of 34,537
Β« previous page Β» next page
Filters