5.3

CVSS4.0

CVE-2025-9244 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaticRoute os command injection

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaticRoute of the file /goform/addStaticRoute. Such manipulation of the argument staticRoute_I…

πŸ“… Published: Aug. 20, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:32 p.m.

5.3

CVSS4.0

CVE-2025-9241 - elunez eladmin exportUser csv injection

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

πŸ“… Published: Aug. 20, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:32 p.m.

4.8

CVSS4.0

CVE-2025-43757 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.…

πŸ“… Published: Aug. 20, 2025, 7:13 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:13 p.m.

7.5

CVSS3.1

CVE-2025-5115 - MadeYouReset HTTP/2 vulnerability

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume…

πŸ“… Published: Aug. 20, 2025, 7:07 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:07 p.m.

5.1

CVSS4.0

CVE-2025-43746 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.…

πŸ“… Published: Aug. 20, 2025, 6:37 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-9240 - elunez eladmin info information disclosure

A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file /auth/info. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

πŸ“… Published: Aug. 20, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:32 p.m.

6.3

CVSS4.0

CVE-2025-9239 - elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryption

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd l…

πŸ“… Published: Aug. 20, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-9238 - Swatadru Exam-Seating-Arrangement Student Login student.php sql injection

A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affected is an unknown function of the file /student.php of the component Student Login. Executing manipulation of the argument email can lead to sql injection. It is possible to laun…

πŸ“… Published: Aug. 20, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

9.3

CVSS3.1

CVE-2025-55746 - Directus allows unauthenticated file upload and file modification due to lacking input sanitization

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' data…

πŸ“… Published: Aug. 20, 2025, 5:58 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2025-9237 - CodeAstro Ecommerce Website Edit Your Account my_account.php cross site scripting

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the …

πŸ“… Published: Aug. 20, 2025, 5:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 5:32 p.m.
Total resulsts: 306438
Page 5 of 30,644
Β« previous page Β» next page
Filters