6.5

CVSS3.1

CVE-2025-47585 - WordPress Booking and Rental Manager plugin <= 2.3.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.8.

📅 Published: June 2, 2025, 7:29 p.m. 🔄 Last Modified: April 23, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2025-48996 - Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint

HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthenticated information disclosure vulnerability exists in the Penn State University deployment of the HAX content management system via the `haxPsuUsage` API endpoint, related to a flat…

📅 Published: June 2, 2025, 7:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-48387 - tar-fs has issue where extract can write outside the specified dir with a specific tarball

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non…

📅 Published: June 2, 2025, 7:20 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.0

CVE-2025-1051 - Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the process…

📅 Published: June 2, 2025, 7:05 p.m. 🔄 Last Modified: Aug. 15, 2025, 4:28 p.m.

4.3

CVSS3.1

CVE-2025-49069 - WordPress Contact Forms by Cimatti plugin <= 1.9.8 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through <= 1.9.8.

📅 Published: June 2, 2025, 6:49 p.m. 🔄 Last Modified: April 23, 2026, 3:31 p.m.

9

CVSS3.1

CVE-2025-5086 - Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through R…

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

📅 Published: June 2, 2025, 5:42 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:27 p.m.

8

CVSS3.1

CVE-2025-20298 - Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgra…

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForw…

📅 Published: June 2, 2025, 5:14 p.m. 🔄 Last Modified: Aug. 4, 2025, 6:19 p.m.

4.3

CVSS3.1

CVE-2025-20297 - Reflected Cross-Site Scripting (XSS) on Splunk Enterprise through dashboard PDF generation component

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that…

📅 Published: June 2, 2025, 5:14 p.m. 🔄 Last Modified: Aug. 1, 2025, 3:44 p.m.

7.8

CVSS3.1

CVE-2025-5036 - RFA File Parsing Use-After-Free Vulnerability

A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

📅 Published: June 2, 2025, 4:55 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2024-1440 - Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploit…

📅 Published: June 2, 2025, 4:51 p.m. 🔄 Last Modified: Oct. 6, 2025, 1:48 p.m.
Total resulsts: 349182
Page 5197 of 34,919
« previous page » next page
Filters