8.9

CVSS4.0

CVE-2025-53373 - Natours has a 1 Click Account take over on reset password via Host Header injection

Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit 7401793a8d9ed0f0c250c4e0ee2815d685d7a70b.

πŸ“… Published: July 7, 2025, 3:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7134 - Campcodes Online Recruitment Management System ajax.php sql injection

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_application. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. Th…

πŸ“… Published: July 7, 2025, 3:32 p.m. πŸ”„ Last Modified: July 13, 2025, 9:47 p.m.

7.5

CVSS3.1

CVE-2025-48367 - Redis DoS Vulnerability due to bad connection error handling

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

πŸ“… Published: July 7, 2025, 3:25 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 3:15 p.m.

7

CVSS3.1

CVE-2025-32023 - Redis allows out of bounds writes in hyperloglog commands leading to RCE

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The b…

πŸ“… Published: July 7, 2025, 3:22 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:16 p.m.

5.4

CVSS3.1

CVE-2025-53487 - ApprovedRevs: Stored Cross-Site Scripting (XSS) via unsanitized system messages

The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are inserted into raw HTML without proper escaping. Attackers can exploit this by injecting JavaScript payloads via the uselang=x-xss language override, which causes crafted message keys…

πŸ“… Published: July 7, 2025, 3:13 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-7057 - Stored XSS in Quiz

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.4…

πŸ“… Published: July 7, 2025, 3:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-53486 - WikiCategoryTagCloud: Reflected Cross-Site Scripting (XSS) via linkstyle attribute in parser functi…

The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly concatenated into inline HTML without escaping. An attacker can inject JavaScript event handlers such as onmouseenter using carefully crafted input via the {{#tag:tagcloud}} parser fun…

πŸ“… Published: July 7, 2025, 3:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7133 - CodeAstro Online Movie Ticket Booking System cross-site request forgery

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be u…

πŸ“… Published: July 7, 2025, 3:02 p.m. πŸ”„ Last Modified: July 9, 2025, 5:24 p.m.

7.8

CVSS3.0

CVE-2025-6663 - GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may v…

πŸ“… Published: July 7, 2025, 2:58 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

9.8

CVSS3.0

CVE-2025-6811 - Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execu…

Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit th…

πŸ“… Published: July 7, 2025, 2:52 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 1:15 p.m.
Total resulsts: 345192
Page 4365 of 34,520
Β« previous page Β» next page
Filters