5.3

CVSS3.1

CVE-2025-3871 - Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may e…

📅 Published: July 16, 2025, 2 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-40918 - Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed,…

📅 Published: July 16, 2025, 2 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-53924 - Emlog vulnerable to stored Cross-site Scripting in links functionality

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter …

📅 Published: July 16, 2025, 1:55 p.m. 🔄 Last Modified: July 21, 2025, 3:17 p.m.

8.2

CVSS3.1

CVE-2025-53923 - Emlog vulnerable to reflected Cross-site Scripting in admin panel

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keywor…

📅 Published: July 16, 2025, 1:53 p.m. 🔄 Last Modified: July 22, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-53892 - Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerr…

Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails …

📅 Published: July 16, 2025, 1:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-40776 - Birthday Attack against Resolvers supporting ECS

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

📅 Published: July 16, 2025, 1:41 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.4

CVSS3.1

CVE-2025-53840 - Icinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be …

📅 Published: July 16, 2025, 1:34 p.m. 🔄 Last Modified: Dec. 11, 2025, 6:26 p.m.

7.3

CVSS3.1

CVE-2025-40923 - Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it…

📅 Published: July 16, 2025, 1:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-34300 - Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

📅 Published: July 16, 2025, 12:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-53758 - Default Credential Vulnerability in Digisol DG-GR6821AC Router

This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the hardcoded default credenti…

📅 Published: July 16, 2025, 11:29 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4617 of 34,919
« previous page » next page
Filters