6.9

CVSS4.0

CVE-2025-8752 - wangzhixuan spring-shiro-training add command injection

A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The explโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 12:02 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 3:25 p.m.

2.3

CVSS4.0

CVE-2025-8751 - Protected Total WebShield Extension Block Page cross site scripting

A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack remโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 7:32 a.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 3:32 p.m.

4.8

CVSS4.0

CVE-2025-8750 - macrozheng mall Add Product Page upload cross site scripting

A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the component Add Product Page. The manipulation of the argument File leads to cross site scripting. The attack can be launโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 7:02 a.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 7:23 p.m.

4.8

CVSS4.0

CVE-2025-8746 - GNU libopts __strstr_sse2 memory corruption

A vulnerability, which was classified as problematic, was found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. This issue โ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 6:02 a.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 3:36 p.m.

4.8

CVSS4.0

CVE-2025-8745 - Weee RICEPO App com.ricepo.app AndroidManifest.xml improper export of android application components

A vulnerability, which was classified as problematic, has been found in Weee RICEPO App 6.17.77 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.ricepo.app. The manipulation leads to improper export of android application components. An attโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:06 p.m.

5.1

CVSS4.0

CVE-2025-4655 -

SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows template editors โ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 4:46 a.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 6:31 p.m.

5.3

CVSS4.0

CVE-2025-4581 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-setโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 4:14 a.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:43 p.m.

6.7

CVSS4.0

CVE-2025-55149 - Path Traversal Vulnerability in PDF Review Function (CWE-22)

Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific researchโ€”from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the review_paper function in backend/app.py. The vulโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2025-55013 - Assemblyline 4 Service Client: Arbitrary Write through path traversal in Client code

The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value returned by the service server and uses it directly as a localโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-55008 - AuthKit React Router: Sensitive auth data rendered in HTML

The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts โ€” specifically sealedSession and accessToken by returโ€ฆ

๐Ÿ“… Published: Aug. 9, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4362 of 34,919
ยซ previous page ยป next page
Filters