9.8

CVSS3.1

CVE-2025-45616 -

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 3:08 p.m.

9.8

CVSS3.1

CVE-2025-45611 -

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 8:50 p.m.

6.5

CVSS3.1

CVE-2025-45240 -

foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 5:44 p.m.

8.8

CVSS3.1

CVE-2025-45321 -

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:39 p.m.

5.3

CVSS3.1

CVE-2025-45239 -

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 5:34 p.m.

9.8

CVSS3.1

CVE-2025-44074 -

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:05 p.m.

9.8

CVSS3.1

CVE-2025-44071 -

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:03 p.m.

6.5

CVSS3.1

CVE-2025-43915 -

In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource exhaustion can occur for Linkerd proxy metrics.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:12 p.m.

6.1

CVSS3.1

CVE-2025-29573 -

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 8:19 p.m.

6.1

CVSS3.1

CVE-2025-27921 -

A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization o…

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 6:40 p.m.
Total resulsts: 343746
Page 5012 of 34,375
Β« previous page Β» next page
Filters