5.1

CVSS4.0

CVE-2025-9167 - SolidInvoice Recurring Invoice recurring cross site scripting

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploit…

πŸ“… Published: Aug. 19, 2025, 8:32 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 8:32 p.m.

4.8

CVSS4.0

CVE-2025-9165 - LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been pub…

πŸ“… Published: Aug. 19, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 8:02 p.m.

4.8

CVSS4.0

CVE-2025-9157 - appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The…

πŸ“… Published: Aug. 19, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 8:02 p.m.

6.5

CVSS3.1

CVE-2025-55740 - Default Credentials in nginx-defender Configuration Files

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml cont…

πŸ“… Published: Aug. 19, 2025, 7:52 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:52 p.m.

5.1

CVSS4.0

CVE-2025-43744 -

A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and…

πŸ“… Published: Aug. 19, 2025, 7:34 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:34 p.m.

6.9

CVSS4.0

CVE-2025-9156 - itsourcecode Sports Management System sports.php sql injection

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public a…

πŸ“… Published: Aug. 19, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:32 p.m.

6.9

CVSS4.0

CVE-2025-9155 - itsourcecode Online Tour and Travel Management System forget_password.php sql injection

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to …

πŸ“… Published: Aug. 19, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:32 p.m.

2.7

CVSS3.1

CVE-2025-2988 - IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.

πŸ“… Published: Aug. 19, 2025, 7:15 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-43743 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view other calendars by all…

πŸ“… Published: Aug. 19, 2025, 7:13 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:13 p.m.

6.9

CVSS4.0

CVE-2025-55737 - flaskBlog arbitrary comment delete

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code th…

πŸ“… Published: Aug. 19, 2025, 7:06 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:06 p.m.
Total resulsts: 306579
Page 48 of 30,658
Β« previous page Β» next page
Filters