8.7

CVSS4.0

CVE-2025-53625 - DynamicPageList3 exposes hidden/suppressed usernames

The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The vulnerability is fixe…

📅 Published: July 10, 2025, 6:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-53549 - Matrix Rust SDK allows SQL injection in the EventCache implementation

The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that…

📅 Published: July 10, 2025, 6:28 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-53542 - Kubernetes Headlamp Allows Arbitrary Command Injection in macOS Process headlamp@codeSign

Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script used in the macOS packaging workflow of the Kubernetes Headlamp project. This issue arises due to the improper use of Node.js's execSync() function with unsanitized input derived …

📅 Published: July 10, 2025, 6:20 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-53371 - DiscordNotifications allows DOS, SSRF, and possible RCE through requests to user-controlled URLs

DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. T…

📅 Published: July 10, 2025, 5:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7410 - code-projects LifeStyle Store cart_remove.php sql injection

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unknown function of the file /cart_remove.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed …

📅 Published: July 10, 2025, 5:02 p.m. 🔄 Last Modified: July 16, 2025, 3:02 p.m.

7.5

CVSS3.1

CVE-2025-53020 - Apache HTTP Server: HTTP/2 DoS by Memory Increase

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

📅 Published: July 10, 2025, 4:59 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.4

CVSS3.1

CVE-2025-49812 - Apache HTTP Server: mod_ssl TLS upgrade attack

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommend…

📅 Published: July 10, 2025, 4:58 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-49630 - Apache HTTP Server: mod_proxy_http2 denial of service

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserv…

📅 Published: July 10, 2025, 4:57 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

9.1

CVSS3.1

CVE-2025-23048 - Apache HTTP Server: mod_ssl access control bypass with session resumption

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of tru…

📅 Published: July 10, 2025, 4:56 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2024-43394 - Apache HTTP Server: SSRF on Windows due to UNC paths

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note:  The Apache HTTP Ser…

📅 Published: July 10, 2025, 4:56 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 4686 of 34,919
« previous page » next page
Filters