6.5

CVSS3.1

CVE-2025-52080 -

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

๐Ÿ“… Published: July 15, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 11, 2025, 6:49 p.m.

7.5

CVSS3.1

CVE-2024-42650 -

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

๐Ÿ“… Published: July 15, 2025, midnight ๐Ÿ”„ Last Modified: July 17, 2025, 5:53 p.m.

9.8

CVSS3.1

CVE-2025-53890 - pyLoad vulnerable to remote code execution through js2py onCaptchaResult

pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoadโ€™s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser and potentially the backend server. Exploitation requires no usโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53889 - Directus missing permission checks for manual trigger Flows

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to the items provided as payload to the Flow. Dependiโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:50 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 9:35 p.m.

5.3

CVSS3.1

CVE-2025-53887 - Directus's exact version number is exposed by the OpenAPI Spec

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint withoutโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:40 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 9:35 p.m.

4.5

CVSS3.1

CVE-2025-53886 - Directus doesn't redact tokens in Flow logs

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:35 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 9:35 p.m.

4.2

CVSS3.1

CVE-2025-53885 - Directus doesn't redact sensitive user data when logging via event hooks

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template stโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:18 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 9:35 p.m.

4

CVSS3.1

CVE-2025-53839 - DRACOON Branding Service vulnerable to Cross-site Scripting

DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users couโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-53836 - XWiki Rendering is vulnerable to RCE attacks when processing nested macros

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11:08 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 5:52 p.m.

9.1

CVSS3.1

CVE-2025-53835 - XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/current` syntax which allows the creation of raw blโ€ฆ

๐Ÿ“… Published: July 14, 2025, 11 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 5:52 p.m.
Total resulsts: 349182
Page 4647 of 34,919
ยซ previous page ยป next page
Filters