6.5

CVSS3.1

CVE-2025-53358 - kotaemon Vulnerable to Path Traversal via Link Upload

kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file paths without validation. The pipeline streams these paths directly and stores them, enabling attackers to t…

πŸ“… Published: July 2, 2025, 3:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-52891 - ModSecurity empty XML tag causes segmentation fault

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least …

πŸ“… Published: July 2, 2025, 3:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-53108 - HomeBox Missing User Authorization

HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and deleting inventory item attachments. This flaw allows authenticated users to perform unauthorized actions on inventory item attachme…

πŸ“… Published: July 2, 2025, 2:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-53492 - Stored XSS in MintyDocs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 2, 2025, 2:41 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 4:55 p.m.

5.4

CVSS3.1

CVE-2025-6725 - Cross-Site Scripting (XSS) in PdfViewer

In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.

πŸ“… Published: July 2, 2025, 2:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53493 - Stored XSS in MintyDocs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2.

πŸ“… Published: July 2, 2025, 2:38 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 5:01 p.m.

7.3

CVSS4.0

CVE-2025-53109 - Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink…

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 res…

πŸ“… Published: July 2, 2025, 2:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-53110 - Model Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path Prefix

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 o…

πŸ“… Published: July 2, 2025, 2:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53494 - Stored XSS in TwoColConflict

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affects Mediawiki - TwoColConflict Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, fr…

πŸ“… Published: July 2, 2025, 2:24 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:33 p.m.

8.9

CVSS4.0

CVE-2025-53006 - Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies…

πŸ“… Published: July 2, 2025, 2:22 p.m. πŸ”„ Last Modified: July 10, 2025, 3:16 p.m.
Total resulsts: 349182
Page 4816 of 34,919
Β« previous page Β» next page
Filters