4.9

CVSS3.1

CVE-2025-46654 -

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 3:14 p.m.

2.9

CVSS3.1

CVE-2025-46656 -

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:24 p.m.

6.1

CVSS3.1

CVE-2025-46652 -

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via secur…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 8:16 p.m.

7.3

CVSS4.0

CVE-2025-46333 - z2d OOB composition could lead to invalid memory access and corruption

z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, and higher-level operations when the anti-aliasing mode is set to `.default` (such as `Context.fill`, `Context.…

πŸ“… Published: April 25, 2025, 8:20 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

8.1

CVSS3.1

CVE-2025-3935 - ScreenConnect Exposure to ASP.NET ViewState Code Injection

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.Β  It is important to note that to obtain these machine keys, privi…

πŸ“… Published: April 25, 2025, 6:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.5

CVSS3.1

CVE-2024-30152 - HCL SX is affected by usage of a weak cryptographic algorithm

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

πŸ“… Published: April 25, 2025, 5:55 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 7:09 p.m.

8.7

CVSS4.0

CVE-2025-3928 - Commvault Web Server unspecified vulnerability

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 fo…

πŸ“… Published: April 25, 2025, 3:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.1

CVSS4.0

CVE-2025-2070 -

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.

πŸ“… Published: April 25, 2025, 3:27 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

5.1

CVSS4.0

CVE-2025-2069 -

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.

πŸ“… Published: April 25, 2025, 3:26 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

5.1

CVSS4.0

CVE-2025-2068 -

An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

πŸ“… Published: April 25, 2025, 3:26 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.
Total resulsts: 344126
Page 5154 of 34,413
Β« previous page Β» next page
Filters