7

CVSS4.0

CVE-2025-48388 - FreeScout Has Insufficient Protection Against CRLF-injection

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a string containing special symbols (\r, \n, \…

📅 Published: May 29, 2025, 9:16 a.m. 🔄 Last Modified: July 11, 2025, 3:22 p.m.

4.7

CVSS3.1

CVE-2025-27151 - redis-check-aof may lead to stack overflow and potential RCE

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allo…

📅 Published: May 29, 2025, 9:07 a.m. 🔄 Last Modified: Dec. 23, 2025, 3:03 p.m.

4.9

CVSS3.1

CVE-2024-52588 - Strapi allows Server-Side Request Forgery in Webhook function

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.

📅 Published: May 29, 2025, 9:02 a.m. 🔄 Last Modified: June 24, 2025, 6:27 p.m.

7.2

CVSS4.0

CVE-2025-4687 - Account pre-hijacking through invite misuse

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account a…

📅 Published: May 29, 2025, 8:59 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-5286 - Bold Builder <= 5.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via additional_set…

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo…

📅 Published: May 29, 2025, 8:22 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

6.4

CVSS3.1

CVE-2025-4670 - Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ed…

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user suppl…

📅 Published: May 29, 2025, 8:22 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2025-5122 - Map Block Leaflet <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Param…

The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a…

📅 Published: May 29, 2025, 8:22 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

8.2

CVSS4.0

CVE-2025-5276 -

All versions of the package mcp-markdownify-server are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpage-to-markdown, bing-search-to-markdown, and youtube-to-markdown tools …

📅 Published: May 29, 2025, 5 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-5273 -

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.

📅 Published: May 29, 2025, 5 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-3755 - Information Disclosure and Denial-of-Service(DoS) Vulnerability in MELSEC iQ-F Series CPU module

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to…

📅 Published: May 29, 2025, 4:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347742
Page 5086 of 34,775
« previous page » next page
Filters