10

CVSS3.1

CVE-2025-53833 - LaRecipe is vulnerable to Server-Side Template Injection attacks

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute…

πŸ“… Published: July 14, 2025, 10:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-53834 - Caido Toast Vulnerable to Reflected Cross-site Scripting

Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s toast UI component in versions prior to 0.49.0. Toast messages may reflect unsanitized user input in certain tools such as Match&Replace and Scope. This could allow an attacker t…

πŸ“… Published: July 14, 2025, 10:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS3.1

CVE-2025-53825 - Dokploy's Preview Deployments are vulnerable to Remote Code Execution

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a pull request on a public repository. This e…

πŸ“… Published: July 14, 2025, 10:44 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 8:46 p.m.

6.4

CVSS4.0

CVE-2025-53824 - WeGIA ReflectedCross-Site Scripting (XSS) vulnerability in endpoint 'cadastro_pet.php' parameter 'm…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the editar_permissoes.php endpoint of the WeGIA application prior to version 3.4.4. This vulnerability allows attackers to …

πŸ“… Published: July 14, 2025, 10:41 p.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

10

CVSS4.0

CVE-2025-53823 - WeGIA vulnerable to SQL Injection (Blind Time-Based) in `processa_deletar_socio.php` parameter `id_…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerability in the endpoint `/WeGIA/html/socio/sistema/processa_deletar_socio.php`, in the `id_socio` parameter. This vulnerability allows the exec…

πŸ“… Published: July 14, 2025, 10:31 p.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2025-53822 - WeGIA vulnerable to Reflected Cross-Site Scripting in endpoint 'relatorio_geracao.php' parameter 't…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `relatorio_geracao.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers t…

πŸ“… Published: July 14, 2025, 10:28 p.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

4.7

CVSS3.1

CVE-2025-53821 - WeGIA vulnerable to Open Redirect in endpoint 'control.php' parameter 'nextPage'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web application prior to version 3.4.5. The control.php endpoint allows to specify an arbitrary URL via the `nextPage` parameter, leading to an uncon…

πŸ“… Published: July 14, 2025, 10:16 p.m. πŸ”„ Last Modified: July 18, 2025, 8:08 p.m.

6.5

CVSS3.1

CVE-2025-53820 - WeGIA vulnerable to Cross-Site Scripting (XSS) Reflected via endpoint 'index.php' parameter 'erro'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `index.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject mal…

πŸ“… Published: July 14, 2025, 8:47 p.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

7.9

CVSS3.1

CVE-2025-53819 - Nix's privilege dropping to build user broke for macOS

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

πŸ“… Published: July 14, 2025, 8:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-53818 - github-kanban-mcp-server Command Injection vulnerability

GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Serv…

πŸ“… Published: July 14, 2025, 8:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4648 of 34,919
Β« previous page Β» next page
Filters