6.8

CVSS3.1

CVE-2025-6233 - Arbitrary file read by system admin via path traversal

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

πŸ“… Published: July 18, 2025, 9:09 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:49 p.m.

6.5

CVSS3.1

CVE-2025-6226 - IDOR in CreatePost API allows for timeboxed message disclosure

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of rec…

πŸ“… Published: July 18, 2025, 8:48 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:49 p.m.

9.8

CVSS3.1

CVE-2025-7444 - LoginPress Pro <= 5.0.1 - Authentication Bypass via WordPress.com OAuth provider

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing u…

πŸ“… Published: July 18, 2025, 8:22 a.m. πŸ”„ Last Modified: April 21, 2026, 4 a.m.

4

CVSS3.1

CVE-2024-32124 -

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request.

πŸ“… Published: July 18, 2025, 8:08 a.m. πŸ”„ Last Modified: July 22, 2025, 5:08 p.m.

6.3

CVSS3.1

CVE-2024-27779 -

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versi…

πŸ“… Published: July 18, 2025, 7:58 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

4.2

CVSS3.1

CVE-2025-6197 - grafana: Open Redirect in Grafana

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

πŸ“… Published: July 18, 2025, 7:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-6023 - grafana: Cross Site Scripting in Grafana

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+se…

πŸ“… Published: July 18, 2025, 7:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-26855 - Extension - joomcar.net - SQL injection in Articles Calendar 1.0.0 - 1.0.1.0007 for Joomla

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

πŸ“… Published: July 18, 2025, 7:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-26854 - Extension - joomcar.net - SQL injection in Articles Good Search 1.0.0 - 1.2.4.0011 for Joomla

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

πŸ“… Published: July 18, 2025, 7:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-7438 - MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitra…

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access a…

πŸ“… Published: July 18, 2025, 6:45 a.m. πŸ”„ Last Modified: April 22, 2026, 2:45 p.m.
Total resulsts: 346551
Page 4335 of 34,656
Β« previous page Β» next page
Filters