10

CVSS3.1

CVE-2025-54122 - Manager-io/Manager allows unauthenticated full read server-side request forgery in "proxy" endpoint

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager Desktop and Server edition versions up to and including 25.7.18.2519. This vulnerability allows an unauโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:28 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-53832 - @translated/lara-mcp vulnerable to command injection in import_tmx tool

Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vulnerability which exists in the @translated/lara-mcp MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call toโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:18 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-53528 - Cadwyn is vulnerable to an XSS attack through its docs page

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code โ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-54071 - RomM's authenticated arbitrary file write vulnerability can lead to Remote Code Execution

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below, an authenticated arbitrary file write vulnerability exists in the /api/saves endpoint. This can lead to Remote Code Execution on the sysโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:09 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54121 - Starlette has possible denial-of-service vector when parsing large files in multipart forms

Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main threadโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.0

CVE-2025-7299 - IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the targeโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 2:05 p.m.

7.8

CVSS3.0

CVE-2025-7325 - IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the targeโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 1:39 p.m.

7.8

CVSS3.0

CVE-2025-7324 - IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the targโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 1:41 p.m.

7.8

CVSS3.0

CVE-2025-7323 - IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the targeโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 1:42 p.m.

7.8

CVSS3.0

CVE-2025-7322 - IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the targโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 1:43 p.m.
Total resulsts: 349182
Page 4558 of 34,919
ยซ previous page ยป next page
Filters