0

CVSS4.0

CVE-2025-3722 -

A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files a…

📅 Published: June 26, 2025, 11:08 a.m. 🔄 Last Modified: Feb. 11, 2026, 9:40 p.m.

7.2

CVSS4.0

CVE-2025-3771 -

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a malicious entry to the registry under the Trelli…

📅 Published: June 26, 2025, 11:05 a.m. 🔄 Last Modified: Feb. 11, 2026, 9:40 p.m.

2.3

CVSS4.0

CVE-2025-6703 - transport/fc.rs: panic attempting to send MAX_DATA with value larger max varint

Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.

📅 Published: June 26, 2025, 9:30 a.m. 🔄 Last Modified: Dec. 3, 2025, 8:41 p.m.

5.9

CVSS3.1

CVE-2024-11584 - cloud-init: Cloud init permissions handling flaw

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.

📅 Published: June 26, 2025, 9:25 a.m. 🔄 Last Modified: Sept. 5, 2025, 3:20 p.m.

7.2

CVSS3.1

CVE-2025-6212 - Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via D…

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The unfiltered field names are stored alongside the sanitized values. Later, the adm…

📅 Published: June 26, 2025, 9:22 a.m. 🔄 Last Modified: July 8, 2025, 11:35 a.m.

6.4

CVSS3.1

CVE-2025-5338 - Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scrip…

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

📅 Published: June 26, 2025, 9:22 a.m. 🔄 Last Modified: April 22, 2026, 3 p.m.

6.4

CVSS3.1

CVE-2025-5842 - Modern Design Library <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via class…

The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac…

📅 Published: June 26, 2025, 9:22 a.m. 🔄 Last Modified: April 22, 2026, 3 p.m.

8.8

CVSS3.1

CVE-2024-6174 - cloud-init: Cloud init permissions flaw

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

📅 Published: June 26, 2025, 9:15 a.m. 🔄 Last Modified: Aug. 26, 2025, 8:48 p.m.

8.6

CVSS4.0

CVE-2025-5459 - OS Command Injection

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.

📅 Published: June 26, 2025, 6:30 a.m. 🔄 Last Modified: Oct. 14, 2025, 5 p.m.

5.1

CVSS4.0

CVE-2025-48497 -

Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.

📅 Published: June 26, 2025, 6:04 a.m. 🔄 Last Modified: Sept. 30, 2025, 8:29 p.m.
Total resulsts: 349182
Page 4881 of 34,919
« previous page » next page
Filters