6.5

CVSS3.1

CVE-2025-52891 - ModSecurity empty XML tag causes segmentation fault

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least …

πŸ“… Published: July 2, 2025, 3:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-53108 - HomeBox Missing User Authorization

HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and deleting inventory item attachments. This flaw allows authenticated users to perform unauthorized actions on inventory item attachme…

πŸ“… Published: July 2, 2025, 2:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-53492 - Stored XSS in MintyDocs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 2, 2025, 2:41 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 4:55 p.m.

5.4

CVSS3.1

CVE-2025-6725 - Cross-Site Scripting (XSS) in PdfViewer

In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.

πŸ“… Published: July 2, 2025, 2:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53493 - Stored XSS in MintyDocs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 2, 2025, 2:38 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 5:01 p.m.

7.3

CVSS4.0

CVE-2025-53109 - Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink…

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 res…

πŸ“… Published: July 2, 2025, 2:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-53110 - Model Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path Prefix

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 o…

πŸ“… Published: July 2, 2025, 2:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53494 - Stored XSS in TwoColConflict

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affects Mediawiki - TwoColConflict Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, fr…

πŸ“… Published: July 2, 2025, 2:24 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:33 p.m.

8.9

CVSS4.0

CVE-2025-53006 - Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies…

πŸ“… Published: July 2, 2025, 2:22 p.m. πŸ”„ Last Modified: July 10, 2025, 3:16 p.m.

8.7

CVSS4.0

CVE-2025-49588 - Linkwarden Local File Inclusion Vulnerability

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other u…

πŸ“… Published: July 2, 2025, 2:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345148
Page 4413 of 34,515
Β« previous page Β» next page
Filters