6.5

CVSS3.1

CVE-2025-46000 -

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 2:15 p.m.

7.1

CVSS3.1

CVE-2025-52169 -

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-50586 -

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:23 p.m.

4.8

CVSS3.1

CVE-2025-50581 -

MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Sept. 23, 2025, 6:04 p.m.

6.5

CVSS3.1

CVE-2025-45157 -

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:44 p.m.

6.5

CVSS3.1

CVE-2025-52163 -

A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-54310 -

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:31 p.m.

4.8

CVSS3.1

CVE-2025-50583 -

StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 7:22 p.m.

6.5

CVSS3.1

CVE-2025-52166 -

Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-7784 - Org.keycloak/keycloak-services: privilege escalation in keycloak admin console (fgapv2 enabled)

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorize…

πŸ“… Published: July 18, 2025, midnight πŸ”„ Last Modified: May 6, 2026, 4:48 p.m.
Total resulsts: 349182
Page 4602 of 34,919
Β« previous page Β» next page
Filters