8.3

CVSS3.1

CVE-2025-54075 - mdc vulnerable to XSS in markdown rendering bypassing HTML filter. (Nยฐ4)

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>โ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54073 - mcp-package-docs vulnerable to command injection in several tools

mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities. A command injection vulnerability exists in the `mcp-package-docs` MCP Server prior to โ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-7791 - PHPGurukul Online Security Guards Hiring System search.php cross site scripting

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remoteโ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:44 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:42 p.m.

4.4

CVSS3.1

CVE-2025-54059 - melange creates SBOM files in APKs with world-writable permissions

melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potโ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-53945 - apko has incorrect permission (0666) in /etc/ld.so.cache and other files

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.

๐Ÿ“… Published: July 18, 2025, 3:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-53888 - RIOT-OS has an ineffective size check that can lead to buffer overflow in link layer address filterโ€ฆ

RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions up to and including 2025.04. Assertions are usually compiled out in production builds. If assertions are the only defense against โ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-7790 - D-Link DI-8100 HTTP Request menu_nat.asp stack-based overflow

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the component HTTP Request Handler. The manipulation of the argument out_addr/in_addr/out_port/proto leads to stack-based buffer overflow. It is possโ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 4:43 p.m.

6.3

CVSS4.0

CVE-2025-7789 - Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insuffโ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:14 p.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 7:35 p.m.

5.4

CVSS3.1

CVE-2025-46732 - OpenCTI's GraphQL IDOR enables authenticated users to modify or delete notifications of other users

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL `NotificationLineNotificationMarkReadMutation` and `NotificationLineNotificationDeleteMutation` mutations of OpenCTI allows an authenticatโ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:05 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:09 p.m.

5.3

CVSS4.0

CVE-2025-7788 - Xuxueli xxl-job SampleXxlJob.java commandJobHandler os command injection

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to os command injection. The attack โ€ฆ

๐Ÿ“… Published: July 18, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 7:52 p.m.
Total resulsts: 346554
Page 4333 of 34,656
ยซ previous page ยป next page
Filters