6.5

CVSS3.1

CVE-2025-45157 -

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:44 p.m.

6.5

CVSS3.1

CVE-2025-52163 -

A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-54310 -

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:31 p.m.

4.8

CVSS3.1

CVE-2025-50583 -

StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:22 p.m.

6.5

CVSS3.1

CVE-2025-46000 -

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 2:15 p.m.

5.3

CVSS3.1

CVE-2025-45156 -

Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:46 p.m.

7.5

CVSS3.1

CVE-2025-50708 -

An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-50586 -

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:23 p.m.

6.5

CVSS3.1

CVE-2025-7784 - Org.keycloak/keycloak-services: privilege escalation in keycloak admin console (fgapv2 enabled)

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorize…

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 9:37 p.m.

8.7

CVSS4.0

CVE-2025-6185 - Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting

Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.

πŸ“… Published: July 17, 2025, 11:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346536
Page 4338 of 34,654
Β« previous page Β» next page
Filters