5.3

CVSS4.0

CVE-2025-41404 -

Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.

πŸ“… Published: June 26, 2025, 6:04 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:28 p.m.

5.3

CVSS3.1

CVE-2025-1754 - Missing Authentication for Critical Function in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource ab…

πŸ“… Published: June 26, 2025, 5:31 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:41 p.m.

3.1

CVSS3.1

CVE-2025-2938 - Business Logic Errors in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval proc…

πŸ“… Published: June 26, 2025, 5:31 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.5

CVSS3.1

CVE-2025-3279 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

πŸ“… Published: June 26, 2025, 5:31 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:42 p.m.

4.3

CVSS3.1

CVE-2025-5315 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI…

πŸ“… Published: June 26, 2025, 5:31 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:43 p.m.

2.7

CVSS3.1

CVE-2025-5846 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-speci…

πŸ“… Published: June 26, 2025, 5:31 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:44 p.m.

8.7

CVSS3.1

CVE-2025-37101 - HPE OneView for VMware vCenter (OV4VC), Local Elevation of Privilege

A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).

πŸ“… Published: June 26, 2025, 5:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.4

CVSS4.0

CVE-2025-6624 -

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in DEBUG or DEBUG/TRA…

πŸ“… Published: June 26, 2025, 5 a.m. πŸ”„ Last Modified: July 9, 2025, 5:53 p.m.

6.4

CVSS3.1

CVE-2025-6540 - web-cam <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via slug Parameter

The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜slug’ parameter in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t…

πŸ“… Published: June 26, 2025, 2:22 a.m. πŸ”„ Last Modified: April 21, 2026, 8:15 p.m.

5.3

CVSS3.1

CVE-2025-5813 - Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Produc…

The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to crea…

πŸ“… Published: June 26, 2025, 2:22 a.m. πŸ”„ Last Modified: April 21, 2026, 8:15 p.m.
Total resulsts: 349182
Page 4882 of 34,919
Β« previous page Β» next page
Filters