8.8

CVSS3.1

CVE-2025-5015 - Parsons AccuWeather Widget Cross-site Scripting

A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.

πŸ“… Published: June 25, 2025, 4:23 p.m. πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.

3.1

CVSS3.1

CVE-2025-4656 - Vault Vulnerable to Recovery Key Cancellation Denial of Service

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17…

πŸ“… Published: June 25, 2025, 4:15 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 6:02 p.m.

10

CVSS3.1

CVE-2025-20281 - Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to i…

πŸ“… Published: June 25, 2025, 4:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.4

CVSS3.1

CVE-2025-20264 - Cisco Identity Services Engine Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms…

πŸ“… Published: June 25, 2025, 4:11 p.m. πŸ”„ Last Modified: July 8, 2025, 2:53 p.m.

7.7

CVSS4.0

CVE-2025-52479 - HTTP.jl vulnerable to CR/LF Injection in URIs

HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF characters. If user input was not otherwise es…

πŸ“… Published: June 25, 2025, 4:06 p.m. πŸ”„ Last Modified: June 26, 2025, 7:52 p.m.

8.7

CVSS4.0

CVE-2025-6615 - D-Link DIR-619L formAutoDetecWAN_wizard4 stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formAutoDetecWAN_wizard4 of the file /goform/formAutoDetecWAN_wizard4. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the att…

πŸ“… Published: June 25, 2025, 4 p.m. πŸ”„ Last Modified: July 14, 2025, 5:18 p.m.

8.7

CVSS4.0

CVE-2025-6614 - D-Link DIR-619L formSetWANType_Wizard5 stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetWANType_Wizard5 of the file /goform/formSetWANType_Wizard5. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be la…

πŸ“… Published: June 25, 2025, 4 p.m. πŸ”„ Last Modified: July 16, 2025, 7:35 p.m.

4.6

CVSS3.1

CVE-2025-50179 - Tuleap missing CSRF protection on tracker reports manipulation

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition prior to version 16.9-1 to trick victims in…

πŸ“… Published: June 25, 2025, 3:48 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 8:53 p.m.

6.3

CVSS4.0

CVE-2025-49845 - Discourse users are able to see their own whispers even after being removed from a group that has b…

Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed `whisper`. However, it has been discovered that users…

πŸ“… Published: June 25, 2025, 3:39 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-6612 - code-projects Inventory Management System removeCategories.php sql injection

A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/removeCategories.php. The manipulation of the argument categoriesId leads to sql injection. The attack may be initiated remot…

πŸ“… Published: June 25, 2025, 3:31 p.m. πŸ”„ Last Modified: June 27, 2025, 6:22 p.m.
Total resulsts: 343919
Page 4367 of 34,392
Β« previous page Β» next page
Filters