4.8

CVSS4.0

CVE-2025-8541 - Portabilis i-Educar public_uf_cad.php cross site scripting

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /intranet/public_uf_cad.php. The manipulation of the argument nome leads to cross site scripting. The attack can be initiated remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 5:46 p.m.

9.3

CVSS4.0

CVE-2025-53417 - File Parsing Deserialization of Untrusted Data in DTM Soft

DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability

๐Ÿ“… Published: Aug. 5, 2025, 2:28 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-8540 - Portabilis i-Educar public_municipio_cad.php cross site scripting

A vulnerability was found in Portabilis i-Educar 2.10. It has been classified as problematic. This affects an unknown part of the file /intranet/public_municipio_cad.php. The manipulation of the argument nome leads to cross site scripting. It is possible to initiate the attack remotely. The exploitโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 5:46 p.m.

4.8

CVSS4.0

CVE-2025-8539 - Portabilis i-Educar public_distrito_cad.php cross site scripting

A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unknown functionality of the file /intranet/public_distrito_cad.php. The manipulation of the argument nome leads to cross site scripting. The attack may be launched remotely. The explโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 5:46 p.m.

4.8

CVSS4.0

CVE-2025-8538 - Portabilis i-Educar novo cross site scripting

A vulnerability has been found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /usuarios/tipos/novo. The manipulation of the argument name/description leads to cross site scripting. The attack can be launched remotelyโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 1:04 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 5:47 p.m.

6.3

CVSS4.0

CVE-2025-8537 - Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to allocation of resources. It is possible to launch the attack reโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Sept. 12, 2025, 3:56 p.m.

4.5

CVSS3.1

CVE-2025-52892 - EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webserver does not strip the double slash, it can causeโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:17 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 5:14 p.m.

7.5

CVSS3.1

CVE-2025-53544 - Trilium Notes is Vulnerable to Brute-force Protection Bypass via Initial Sync Seed Retrieval

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoint allows unauthenticated attackers to guess the login passwโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:14 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-54119 - ADOdb's sqlite3 driver allows SQL injection

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a sqlite3 database andโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:12 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54130 - Cursor Agent is vulnerable prompt injection via Editor Special Files

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive editor files, such as the .vscode/settings.jsโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:12 a.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 1:38 a.m.
Total resulsts: 347960
Page 4290 of 34,796
ยซ previous page ยป next page
Filters