6.5

CVSS3.1

CVE-2025-45820 -

Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 7:41 p.m.

5.5

CVSS3.1

CVE-2025-37814 - tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT

In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as it turns out, (1) the logโ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 12, 2025, 9:38 p.m.

6.1

CVSS3.1

CVE-2025-28074 -

phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScโ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 6:39 p.m.

2

CVSS4.0

CVE-2024-55651 - i-Educar Stored Cross-Site Scripting vulnerability

i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuรกrio) input field. Through this attacker vectorโ€ฆ

๐Ÿ“… Published: May 7, 2025, 11:49 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 7:44 p.m.

7.5

CVSS3.1

CVE-2025-46727 - Unbounded-Parameter DoS in Rack::QueryParser

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests wiโ€ฆ

๐Ÿ“… Published: May 7, 2025, 11:07 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 7:44 p.m.

4.2

CVSS3.1

CVE-2025-32441 - Rack session gets restored after deletion

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the begโ€ฆ

๐Ÿ“… Published: May 7, 2025, 11:01 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 7:48 p.m.

6.5

CVSS3.1

CVE-2025-0936 - On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File Transโ€ฆ

On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TAโ€ฆ

๐Ÿ“… Published: May 7, 2025, 10:52 p.m. ๐Ÿ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.9

CVSS4.0

CVE-2025-35939 - Craft CMS stores user-provided content in session files

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at 'โ€ฆ

๐Ÿ“… Published: May 7, 2025, 10:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.7

CVSS4.0

CVE-2025-41431 - TMM Vulnerability

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

๐Ÿ“… Published: May 7, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Aug. 6, 2025, 4:25 p.m.

8.5

CVSS4.0

CVE-2025-31644 - Appliance mode BIG-IP iControl REST and tmsh vulnerability

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attackeโ€ฆ

๐Ÿ“… Published: May 7, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 343980
Page 4979 of 34,398
ยซ previous page ยป next page
Filters