5.3

CVSS3.1

CVE-2025-52576 - Kanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection Bypass

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force protection bypass. By analyzing login behavior and abusing trusted HTTP headers, an attacker can determine valid …

πŸ“… Published: June 25, 2025, 4:46 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:23 p.m.

6.6

CVSS4.0

CVE-2025-52569 - GitHub.jl lacks validation for user-provided fields

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field. These inputs are not val…

πŸ“… Published: June 25, 2025, 4:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS4.0

CVE-2025-52483 - Registrator.jl Vulnerable to Argument Injection and Command Injection

Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can occur within the `w…

πŸ“… Published: June 25, 2025, 4:39 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 4:01 p.m.

8.1

CVSS4.0

CVE-2025-52480 - Registrator.jl Argument Injection Vulnerability

Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettr…

πŸ“… Published: June 25, 2025, 4:37 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 4:02 p.m.

9.3

CVSS4.0

CVE-2025-49153 - Path Traversal in MICROSENS NMP Web+

The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.

πŸ“… Published: June 25, 2025, 4:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-49152 - Insufficient Session Expiration in MICROSENS NMP Web+

The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.

πŸ“… Published: June 25, 2025, 4:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-49151 - Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+

The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.

πŸ“… Published: June 25, 2025, 4:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-6616 - D-Link DIR-619L formSetWAN_Wizard51 stack-based overflow

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWAN_Wizard51 of the file /goform/formSetWAN_Wizard51. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack can be initiated remot…

πŸ“… Published: June 25, 2025, 4:31 p.m. πŸ”„ Last Modified: July 14, 2025, 5:18 p.m.

10

CVSS3.1

CVE-2025-20282 - Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks th…

πŸ“… Published: June 25, 2025, 4:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-5015 - Parsons AccuWeather Widget Cross-site Scripting

A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.

πŸ“… Published: June 25, 2025, 4:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4892 of 34,919
Β« previous page Β» next page
Filters