4.3

CVSS3.1

CVE-2024-3509 - Stored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text Ediโ€ฆ

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative โ€ฆ

๐Ÿ“… Published: June 2, 2025, 4:44 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 1:48 p.m.

6.8

CVSS3.1

CVE-2024-7074 - Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remโ€ฆ

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server. By leveraging this vulnerability, an aโ€ฆ

๐Ÿ“… Published: June 2, 2025, 4:42 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-7073 - Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin Services

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the networโ€ฆ

๐Ÿ“… Published: June 2, 2025, 4:38 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 1:46 p.m.

6.9

CVSS4.0

CVE-2025-48995 - SignXML's signature verification with HMAC is vulnerable to a timing attack

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML prior to 4.0.4 are vulnerable to a potentiaโ€ฆ

๐Ÿ“… Published: June 2, 2025, 4:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-48994 - SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML prior to 4.0.4 are vulnerable to a potentiaโ€ฆ

๐Ÿ“… Published: June 2, 2025, 4:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-48941 - MyBB may disclosure unviewable threads' titles in searches

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specified text in the title. The visibility state (โ€ฆ

๐Ÿ“… Published: June 2, 2025, 3:58 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 3:14 p.m.

7.2

CVSS3.1

CVE-2025-48940 - MyBB's upgrade component vulnerable to local file inclusion

MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocโ€ฆ

๐Ÿ“… Published: June 2, 2025, 3:52 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 3:18 p.m.

7.5

CVSS3.1

CVE-2025-48866 - ModSecurity has possible DoS vulnerability in sanitiseArg action

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an aliaโ€ฆ

๐Ÿ“… Published: June 2, 2025, 3:46 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 6:11 p.m.

8.4

CVSS3.1

CVE-2024-48877 -

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

๐Ÿ“… Published: June 2, 2025, 3 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

8.4

CVSS3.1

CVE-2024-52035 -

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

๐Ÿ“… Published: June 2, 2025, 3 p.m. ๐Ÿ”„ Last Modified: Feb. 18, 2026, 2:42 p.m.
Total resulsts: 346571
Page 4937 of 34,658
ยซ previous page ยป next page
Filters