9.3

CVSS4.0

CVE-2024-12223 - Stored Cross-site Scripting (XSS) in Nutanix Prism Central

Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

πŸ“… Published: Aug. 20, 2025, 12:44 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:44 a.m.

0.0

CVE-2025-9132 -

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Aug. 20, 2025, 12:41 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:41 a.m.

5.1

CVSS4.0

CVE-2025-9193 - TOTVS Portal Meu RH Password Reset redirect

A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to open redirect. The attack may be performed from a remote location. The exploit has been published and m…

πŸ“… Published: Aug. 20, 2025, 12:02 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:02 a.m.

0.0

CVE-2025-55503 -

Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 1:34 p.m.

0.0

CVE-2025-55482 -

Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:30 p.m.

0.0

CVE-2025-50902 -

Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 7:10 p.m.

0.0

CVE-2025-28041 -

Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 4:50 p.m.

0.0

CVE-2024-57157 -

Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 3:45 p.m.

0.0

CVE-2024-57152 -

Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 6:55 p.m.

0.0

CVE-2024-57154 -

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 7:42 p.m.
Total resulsts: 306654
Page 50 of 30,666
Β« previous page Β» next page
Filters