4.4

CVSS3.1

CVE-2025-43861 - ManageWiki Vulnerable to Self-XSS in review dialog via unsanitized field reflection

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dial…

πŸ“… Published: April 24, 2025, 8:49 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:41 p.m.

4.6

CVSS3.1

CVE-2022-44759 - HCL Leap is affected by Cross-site scripting (XSS)

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

πŸ“… Published: April 24, 2025, 8:38 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

4.6

CVSS3.1

CVE-2022-44760 - HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

3.2

CVSS3.1

CVE-2023-37516 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

3.2

CVSS3.1

CVE-2024-30127 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

πŸ“… Published: April 24, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

9.3

CVSS4.0

CVE-2025-26382 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool

Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

πŸ“… Published: April 24, 2025, 7:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-43859 - h11 accepts some malformed Chunked-Encoding bodies

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires th…

πŸ“… Published: April 24, 2025, 6:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS3.1

CVE-2025-43858 - YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with…

πŸ“… Published: April 24, 2025, 6:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-31324 - Missing Authorization check in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability…

πŸ“… Published: April 24, 2025, 4:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2023-37534 - HCL Leap is affected by a Cross-site scripting (XSS) vulnerability

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

πŸ“… Published: April 24, 2025, 4:27 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.
Total resulsts: 344716
Page 5222 of 34,472
Β« previous page Β» next page
Filters