9.3

CVSS4.0

CVE-2025-55736 - flaskBlog allows arbitrary privilege escalation

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.

πŸ“… Published: Aug. 19, 2025, 7:04 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

5.4

CVSS3.1

CVE-2025-33008 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File GatewayΒ 6.2.1.0Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi…

πŸ“… Published: Aug. 19, 2025, 7:03 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:03 p.m.

6.9

CVSS4.0

CVE-2025-9154 - itsourcecode Online Tour and Travel Management System page-login.php sql injection

A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been published and may…

πŸ“… Published: Aug. 19, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

5.3

CVSS4.0

CVE-2025-55735 - flaskBlog Stored XSS Vulnerability

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe filter, that tells the engine to not escape …

πŸ“… Published: Aug. 19, 2025, 6:56 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

6.9

CVSS4.0

CVE-2025-43745 -

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote…

πŸ“… Published: Aug. 19, 2025, 6:39 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

6.9

CVSS4.0

CVE-2025-55734 - flaskBlo Authorization Bypass

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when a user is trying to access the admin page, b…

πŸ“… Published: Aug. 19, 2025, 6:38 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

5.3

CVSS4.0

CVE-2025-9153 - itsourcecode Online Tour and Travel Management System travellers.php unrestricted upload

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument photo results in unrestricted upload. The attack can be launched remotely. The exploit is…

πŸ“… Published: Aug. 19, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.

9.7

CVSS3.1

CVE-2025-55733 - DeepChat One-click Remote Code Execution through Custom URL Handling

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they contro…

πŸ“… Published: Aug. 19, 2025, 6:26 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 6:26 p.m.

9.8

CVSS3.1

CVE-2025-55306 - GenX_FX authentication bypass in JWT validation

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud…

πŸ“… Published: Aug. 19, 2025, 6:19 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 6:19 p.m.

5.1

CVSS4.0

CVE-2025-43737 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.

πŸ“… Published: Aug. 19, 2025, 6:13 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:31 p.m.
Total resulsts: 306579
Page 49 of 30,658
Β« previous page Β» next page
Filters