6.1

CVSS3.1

CVE-2025-51531 -

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/scripts/cgiip.exe/WService. The vendor has stated that โ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:38 p.m.

7

CVSS3.1

CVE-2025-45766 -

poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is noโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 17, 2025, 4:15 a.m.

7.5

CVSS3.1

CVE-2025-51040 -

Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2.

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 7:38 p.m.

6.5

CVSS3.1

CVE-2025-50233 -

A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access sensitive files outsideโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:34 p.m.

8.7

CVSS4.0

CVE-2025-54872 - onion-site-template tor Secrets Baked Into Image

onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were abโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 11:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54879 - Mastodon eโ€‘mail throttle misconfiguration allows unlimited email confirmations against unconfirmed โ€ฆ

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical configuration error where the eโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 11:39 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 1:57 p.m.

6.9

CVSS4.0

CVE-2025-54571 - ModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP responseโ€™s Content-Type, which could lead to several issues depending on the HTTP scenario. For example, we have demonstrateโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 11:39 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

8.7

CVSS4.0

CVE-2025-54884 - Vision UI security-kit.js: Potential Uncontrolled Resource Allocation Vulnerability

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to Denial of Service (DoSโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 11:37 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-54883 - Vision UI's security-kit Contains Cryptographic Weakness

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the getSecureRandomInt function in security-kit versions prior to 3.5.0 (packaged in Vision-ui <= 1.4.0) contains a critical cryptographic weakness. Due to a silent 32-bit inโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 11:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-54876 - Jans CLI stores plaintext passwords in the local cli_cmd.log file

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.

๐Ÿ“… Published: Aug. 5, 2025, 11:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4403 of 34,919
ยซ previous page ยป next page
Filters