6.5

CVSS4.0

CVE-2025-32430 - XWiki Platform contains Reflected XSS vulnerability in two templates

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabilities, allowing an attacker to execute malic…

📅 Published: Aug. 5, 2025, 11:27 p.m. 🔄 Last Modified: Sept. 2, 2025, 7:24 p.m.

4.8

CVSS4.0

CVE-2025-8571 - Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS)…

Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an adm…

📅 Published: Aug. 5, 2025, 10:37 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:54 p.m.

2

CVSS4.0

CVE-2025-8573 - Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerabilit…

📅 Published: Aug. 5, 2025, 10:36 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:54 p.m.

7.7

CVSS4.0

CVE-2025-53534 - RatPanel can perform remote command execution without authorization

RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take over hosts managed b…

📅 Published: Aug. 5, 2025, 8:58 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2012-10024 - XBMC ≤ 11.0 Web Server Path Traversal

XBMC version 11, including builds up to the 2012-11-04 nightly release, contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intend…

📅 Published: Aug. 5, 2025, 8:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2012-10027 - WordPress Plugin WP-Property <= 1.35.0 PHP File Upload

WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.

📅 Published: Aug. 5, 2025, 8:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2012-10026 - WordPress Plugin Asset-Manager <= 2.0 PHP File Upload

The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary dire…

📅 Published: Aug. 5, 2025, 8:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2012-10025 - WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST p…

📅 Published: Aug. 5, 2025, 8:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2012-10035 - Turbo FTP Server 1.30.823/826 PORT Command Buffer Overflow

Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges.

📅 Published: Aug. 5, 2025, 8:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2013-10065 - Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS

A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange data, including a no…

📅 Published: Aug. 5, 2025, 8:05 p.m. 🔄 Last Modified: Nov. 21, 2025, 12:20 a.m.
Total resulsts: 347986
Page 4285 of 34,799
« previous page » next page
Filters