5.4

CVSS3.1

CVE-2025-46959 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation …

📅 Published: July 16, 2025, 3:52 p.m. 🔄 Last Modified: July 22, 2025, 9:41 p.m.

6.4

CVSS4.0

CVE-2025-53931 - WeGIA vulnerable to Stored Cross-Site Scripting via endpoint `adicionar_raca.php` parameter `raca`

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_raca.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inje…

📅 Published: July 16, 2025, 3:50 p.m. 🔄 Last Modified: July 25, 2025, 4:36 p.m.

6.4

CVSS4.0

CVE-2025-53930 - WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint 'adicionar_especie.php' paramete…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_especie.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to i…

📅 Published: July 16, 2025, 3:49 p.m. 🔄 Last Modified: July 25, 2025, 4:38 p.m.

6.4

CVSS4.0

CVE-2025-53929 - WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint `adicionar_cor.php` parameter `c…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cor.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to injec…

📅 Published: July 16, 2025, 3:44 p.m. 🔄 Last Modified: July 25, 2025, 4:38 p.m.

6.1

CVSS3.1

CVE-2025-53926 - Emlog has Stored Cross-site Scripting vulnerability due to error

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefo…

📅 Published: July 16, 2025, 3:37 p.m. 🔄 Last Modified: Aug. 14, 2025, 8:37 p.m.

8.7

CVSS4.0

CVE-2025-5994 - Cache poisoning via the ECS-enabled Rebirthday Attack

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to ups…

📅 Published: July 16, 2025, 2:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-53925 - Emlog has Stored Cross-site Scripting vulnerability in file upload functionality

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload an .s…

📅 Published: July 16, 2025, 2:21 p.m. 🔄 Last Modified: Aug. 14, 2025, 8:38 p.m.

7.1

CVSS3.1

CVE-2025-37104 - HPE Telco Service Orchestrator Software, Authenticated SQL Injection

A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clien…

📅 Published: July 16, 2025, 2:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-40913 - Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an in…

Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

📅 Published: July 16, 2025, 2:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-40919 - Authen::DigestMD5 versions 0.01 through 0.04 for Perl generate the cnonce insecurely

Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not le…

📅 Published: July 16, 2025, 2:04 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4616 of 34,919
« previous page » next page
Filters