2

CVSS4.0

CVE-2025-4599 -

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based …

πŸ“… Published: Aug. 4, 2025, 9:18 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 4:25 p.m.

5.3

CVSS4.0

CVE-2025-8526 - Exrick xboot UploadController.java upload unrestricted upload

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/UploadController.java. The manipulation of the argument File leads to unrestric…

πŸ“… Published: Aug. 4, 2025, 9:02 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 12:15 p.m.

6.9

CVSS4.0

CVE-2025-8525 - Exrick xboot Spring Boot Admin/Spring Actuator information disclosure

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Boot Admin/Spring Actuator. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been discl…

πŸ“… Published: Aug. 4, 2025, 8:32 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 12:17 p.m.

4.8

CVSS4.0

CVE-2025-8524 - Boquan DotWallet App com.boquanhash.dotwallet AndroidManifest.xml improper export of android applic…

A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipulation leads to improper export of android application compone…

πŸ“… Published: Aug. 4, 2025, 8:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-8523 - RiderLike Fruit Crush-Brain App com.fruitcrush.fun AndroidManifest.xml improper export of android a…

A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.fruitcrush.fun. The manipulation leads to improper export of android applic…

πŸ“… Published: Aug. 4, 2025, 7:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-8522 - givanz Vvvebjs node.js save.php path traversal

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The complexity of …

πŸ“… Published: Aug. 4, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:21 p.m.

8.4

CVSS3.1

CVE-2025-26476 -

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

πŸ“… Published: Aug. 4, 2025, 6:44 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

8.3

CVSS3.1

CVE-2025-21120 -

Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

πŸ“… Published: Aug. 4, 2025, 6:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

4.8

CVSS4.0

CVE-2025-8521 - givanz Vvveb Add Type post-types cross site scripting

A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects some unknown processing of the file /vadmin123/index.php?module=settings/post-types of the component Add Type Handler. The manipulation leads to cross site scripting. The attack may …

πŸ“… Published: Aug. 4, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:21 p.m.

7.5

CVSS3.1

CVE-2025-38741 -

Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

πŸ“… Published: Aug. 4, 2025, 6:22 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 5:57 p.m.
Total resulsts: 347940
Page 4293 of 34,794
Β« previous page Β» next page
Filters