5.1

CVSS4.0

CVE-2025-6698 - LabRedesCefetRJ WeGIA Adicionar tipo adicionar_tipoSaida.php cross site scripting

A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /html/matPat/adicionar_tipoSaida.php of the component Adicionar tipo. The manipulation of the argument Insira o novo tipo leads to cross site …

πŸ“… Published: June 26, 2025, 3 p.m. πŸ”„ Last Modified: July 1, 2025, 5:46 p.m.

5.1

CVSS4.0

CVE-2025-6697 - LabRedesCefetRJ WeGIA Adicionar tipo adicionar_tipoEntrada.php cross site scripting

A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /html/matPat/adicionar_tipoEntrada.php of the component Adicionar tipo. The manipulation of the argument Insira o novo tipo leads to …

πŸ“… Published: June 26, 2025, 3 p.m. πŸ”„ Last Modified: July 1, 2025, 5:57 p.m.

8.9

CVSS4.0

CVE-2025-53007 - arduino-esp32 vulnerable to CRLF injection in WebServer.cpp

arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response Splitting vulnerability. The `sendHeader` function takes arbitrary input for the HTTP header name and value, concatenates them into an HTTP header line, and appends this to the outgoi…

πŸ“… Published: June 26, 2025, 2:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-53002 - LLaMA-Factory Remote Code Execution (RCE) Vulnerability

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, al…

πŸ“… Published: June 26, 2025, 2:40 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:49 p.m.

7.6

CVSS3.1

CVE-2025-52902 - File Browser has Stored Cross-Site Scripting vulnerability

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a…

πŸ“… Published: June 26, 2025, 2:37 p.m. πŸ”„ Last Modified: July 10, 2025, 1:09 a.m.

5.5

CVSS3.1

CVE-2025-52900 - File Browser has Insecure File Permissions

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same is true for the dat…

πŸ“… Published: June 26, 2025, 2:35 p.m. πŸ”„ Last Modified: July 10, 2025, 1:17 a.m.

7.5

CVSS3.1

CVE-2025-52887 - cpp-httplib has unlimited number of http header fields, which causes memory leak

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the library does not limit the number of headers, and the memory associated with the headers will not be released when the connection is disconnected. Th…

πŸ“… Published: June 26, 2025, 2:31 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 7:15 p.m.

5.1

CVSS4.0

CVE-2025-6696 - LabRedesCefetRJ WeGIA Cadastro de Atendio Cadastro_Atendido.php cross site scripting

A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been classified as problematic. Affected is an unknown function of the file /html/atendido/Cadastro_Atendido.php of the component Cadastro de Atendio. The manipulation of the argument Nome/Sobrenome leads to cross site scripting. It i…

πŸ“… Published: June 26, 2025, 2:31 p.m. πŸ”„ Last Modified: July 1, 2025, 6 p.m.

7.5

CVSS3.1

CVE-2025-6710 - Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Rec…

MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could …

πŸ“… Published: June 26, 2025, 2:09 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 2:04 p.m.

6

CVSS3.1

CVE-2025-52573 - Command Injection in MCP Server ios-simulator-mcp

iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulators. Versions prior to 1.3.3 are written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation.…

πŸ“… Published: June 26, 2025, 2:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4878 of 34,919
Β« previous page Β» next page
Filters