5.3

CVSS3.1

CVE-2023-38327 -

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 8:50 p.m.

6.7

CVSS3.1

CVE-2025-7519 - Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is …

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.1

CVSS3.1

CVE-2023-38329 -

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web script or HTML into the "user" HTTP/GET parameter, which reflects its input without saniti…

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 8:49 p.m.

5.8

CVSS3.1

CVE-2025-53864 - com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id …

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-51591 - pandoc: Server-Side Request Forgery in Pandoc

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilitie…

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-52994 -

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-53471 - Emerson ValveLink Products Improper Input Validation

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

πŸ“… Published: July 10, 2025, 11:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-48496 - Emerson ValveLink Products Uncontrolled Search Path Element

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

πŸ“… Published: July 10, 2025, 11:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-46358 - Emerson ValveLink Products Protection Mechanism Failure

Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

πŸ“… Published: July 10, 2025, 11:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-50109 - Emerson ValveLink Products Cleartext Storage of Sensitive Information in Memory

Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.

πŸ“… Published: July 10, 2025, 11:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4679 of 34,919
Β« previous page Β» next page
Filters