10

CVSS3.1

CVE-2025-54119 - ADOdb's sqlite3 driver allows SQL injection

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a sqlite3 database andโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:12 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54130 - Cursor Agent is vulnerable prompt injection via Editor Special Files

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive editor files, such as the .vscode/settings.jsโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:12 a.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 1:38 a.m.

8.6

CVSS3.1

CVE-2025-54135 - Cursor Agent is vulnerable to prompt injection via MCP Special Files

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the .cursor/mcp.json file don'โ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:11 a.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 1:36 a.m.

6.9

CVSS4.0

CVE-2025-54387 - IPX is Vulnerable to Path Traversal via Prefix Matching Bypass

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used to check whether a path is within allowed directories is vulnerable to path prefix bypass when the allowed directories do not end with a path separatorโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:10 a.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:32 p.m.

7.7

CVSS3.1

CVE-2025-54780 - glpi-screenshot-plugin exposes local files in /ajax/screenshot.php

The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.

๐Ÿ“… Published: Aug. 5, 2025, 12:08 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-54794 - Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file acceโ€ฆ

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files outside the CWD. Successful exploitation depends on the presence of (or ability toโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:08 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 6:01 p.m.

8.7

CVSS4.0

CVE-2025-54795 - Claude Code echo command allowed bypass of user approval prompt for command execution

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code contexโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:07 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2025, 2:05 p.m.

9.8

CVSS3.1

CVE-2025-54802 - pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execโ€ฆ

pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in pyLoad-ng CNL Blueprint via package parameter, allowing Arbitrary File Write which leads to Remote Code Execution (RCE). The addcrypted endpโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:06 a.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:32 p.m.

7.9

CVSS4.0

CVE-2025-54803 - js-toml is vulnerable to Prototype Pollution

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML input. This is fixed iโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:06 a.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:32 p.m.

6.5

CVSS3.1

CVE-2025-54804 - Russh is missing an overflow check during channel windows adjust

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:05 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 6:32 p.m.
Total resulsts: 349182
Page 4413 of 34,919
ยซ previous page ยป next page
Filters