9.4

CVSS4.0

CVE-2025-54060 - WeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependen…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_editarInfoPessoal.php` endpoint. This vulner…

📅 Published: July 17, 2025, 2:17 p.m. 🔄 Last Modified: July 30, 2025, 7:57 p.m.

9.4

CVSS4.0

CVE-2025-54058 - WeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependen…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_editarEndereco.php` endpoint. This vulnerabi…

📅 Published: July 17, 2025, 2:09 p.m. 🔄 Last Modified: July 30, 2025, 7:57 p.m.

9.4

CVSS4.0

CVE-2025-53946 - WeGIA vulnerable to SQL Injection in endpoint profile_paciente.php parameter id_fichamedica

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.5 in the `id_funcionario` parameter of the `/html/saude/profile_paciente.php` endpoint. This vulnerability allows attacker t…

📅 Published: July 17, 2025, 2:02 p.m. 🔄 Last Modified: July 30, 2025, 7:57 p.m.

6.1

CVSS3.1

CVE-2025-53941 - Hollo renders posts received with form elements and allows submission

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.

📅 Published: July 17, 2025, 2:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-1713 - deadlock potential with VT-d and legacy PCI device pass-through

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock.

📅 Published: July 17, 2025, 1:59 p.m. 🔄 Last Modified: Jan. 13, 2026, 10:16 p.m.

4.6

CVSS3.1

CVE-2025-53928 - MaxKB has RCE in MCP call

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.

📅 Published: July 17, 2025, 1:56 p.m. 🔄 Last Modified: Aug. 2, 2025, 1:35 a.m.

4.6

CVSS3.1

CVE-2025-53927 - MaxKB sandbox bypass

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2` method in Python to copy the command they …

📅 Published: July 17, 2025, 1:50 p.m. 🔄 Last Modified: Aug. 2, 2025, 1:34 a.m.

9.1

CVSS3.1

CVE-2025-53909 - mailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification Template

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows te…

📅 Published: July 17, 2025, 1:47 p.m. 🔄 Last Modified: Sept. 11, 2025, 8:16 p.m.

6.5

CVSS3.1

CVE-2025-40924 - Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Catalyst context. This information is of low entropy. The PID wi…

📅 Published: July 17, 2025, 1:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-5346 - File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner applica…

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is p…

📅 Published: July 17, 2025, 12:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4609 of 34,919
« previous page » next page
Filters