9.1

CVSS3.1

CVE-2025-54887 - jwe: Missing AES-GCM authentication tag validation in encrypted JWEs

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. This puts users at risk becau…

πŸ“… Published: Aug. 8, 2025, 12:06 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-54886 - skops: Card.get_model does not block arbitrary code execution

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code execution. The Card.get_model function supports both joblib and skops for model loading. When loading .sk…

πŸ“… Published: Aug. 8, 2025, 12:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS4.0

CVE-2025-54793 - Astro: Duplicate trailing slash feature can lead to Open Redirects

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs s…

πŸ“… Published: Aug. 8, 2025, 12:02 a.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:14 p.m.

5.3

CVSS4.0

CVE-2025-8703 - Wanzhou WOES Intelligent Optimization Energy Saving System Environmental Real-Time Data Module GetA…

A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of the file /WEAS_HomePage/GetAreaTrendChartData of the component Environmental Real-Time Data Module. The manipulation of the argument energyI…

πŸ“… Published: Aug. 8, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 3, 2025, 3:29 p.m.

6.8

CVSS4.0

CVE-2025-54368 - uv is vulnerable to ZIP payload obfuscation through parsing differentials

uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the archive's central directory. An attacker could contrive a ZIP archive that would extract with legitim…

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-52914 -

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQ…

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: Aug. 8, 2025, 8:17 p.m.

8.8

CVSS3.1

CVE-2020-9322 -

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-50928 -

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:35 p.m.

6.5

CVSS3.1

CVE-2025-50467 -

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to build a SQL query.

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: Aug. 12, 2025, 7:51 a.m.

9.8

CVSS3.1

CVE-2025-52913 -

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker …

πŸ“… Published: Aug. 8, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4371 of 34,919
Β« previous page Β» next page
Filters