7

CVSS3.1

CVE-2025-40915 - Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens

Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.

πŸ“… Published: June 11, 2025, 5:09 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

6.8

CVSS3.1

CVE-2025-4673 - Sensitive headers not cleared on cross-origin redirect in net/http

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

πŸ“… Published: June 11, 2025, 4:42 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

7.5

CVSS3.1

CVE-2025-22874 - Usage of ExtKeyUsageAny disables policy validation in crypto/x509

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

πŸ“… Published: June 11, 2025, 4:42 p.m. πŸ”„ Last Modified: June 16, 2025, 8:26 p.m.

7.2

CVSS3.1

CVE-2025-6002 - VirtueMart - Unrestricted File Upload

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on s…

πŸ“… Published: June 11, 2025, 4:26 p.m. πŸ”„ Last Modified: June 24, 2025, 9:51 a.m.

8.3

CVSS3.1

CVE-2025-6001 - VirtueMart - Cross Site Request Forgery (CSRF)

A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.

πŸ“… Published: June 11, 2025, 4:26 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

2.4

CVSS4.0

CVE-2025-1699 -

An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

πŸ“… Published: June 11, 2025, 4:14 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

2.4

CVSS4.0

CVE-2025-1698 -

Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.

πŸ“… Published: June 11, 2025, 4:14 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

6.3

CVSS4.0

CVE-2025-26383 -

The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.

πŸ“… Published: June 11, 2025, 3:36 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

7.3

CVSS3.1

CVE-2025-49148 - ClipShare Server Allows Local Privilege Escalation via DLL Hijacking

ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system libraries like CRYPTBASE.dll and WindowsCodecs.dll from its own directory before the system path. A local, non-privileged…

πŸ“… Published: June 11, 2025, 2:53 p.m. πŸ”„ Last Modified: June 12, 2025, 4:06 p.m.

7.1

CVSS3.1

CVE-2025-48447 - Lightgallery - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-069

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.

πŸ“… Published: June 11, 2025, 2:37 p.m. πŸ”„ Last Modified: June 20, 2025, 2:41 p.m.
Total resulsts: 343048
Page 4436 of 34,305
Β« previous page Β» next page
Filters