5.3

CVSS3.1

CVE-2025-31120 - NamelessMC Vulnerable to Cookie-Based View Count Manipulation

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application relies on a client-side cookie (nl-topic-[t…

πŸ“… Published: April 18, 2025, 3:52 p.m. πŸ”„ Last Modified: May 13, 2025, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-31118 - NamelessMC Has Forum Reply Submission Time Limit Bypass

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously post replies without any time restriction, re…

πŸ“… Published: April 18, 2025, 3:52 p.m. πŸ”„ Last Modified: May 13, 2025, 3:27 p.m.

7.3

CVSS3.1

CVE-2025-30357 - NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator de…

πŸ“… Published: April 18, 2025, 3:51 p.m. πŸ”„ Last Modified: May 13, 2025, 3:40 p.m.

7.1

CVSS3.1

CVE-2025-30158 - NamelessMC Forum iframe width/height abuse causing UI-based Denial of Service

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attributes. This allows an authenticated attacker to…

πŸ“… Published: April 18, 2025, 3:50 p.m. πŸ”„ Last Modified: May 13, 2025, 3:40 p.m.

7.5

CVSS3.1

CVE-2025-29784 - NamelessMC Has Lack of Length Validation for s Parameter in GET Requests

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performan…

πŸ“… Published: April 18, 2025, 3:50 p.m. πŸ”„ Last Modified: May 13, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-27599 - Element X Android vulnerable to loading malicious web pages via received intent

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temp…

πŸ“… Published: April 18, 2025, 3:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-32434 - PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_o…

πŸ“… Published: April 18, 2025, 3:48 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 7:16 a.m.

9.8

CVSS3.1

CVE-2025-29953 - Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious re…

πŸ“… Published: April 18, 2025, 3:23 p.m. πŸ”„ Last Modified: July 9, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2025-3792 - SeaCMS admin_link.php sql injection

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may be initiated remotely. The exploit has been disc…

πŸ“… Published: April 18, 2025, 3 p.m. πŸ”„ Last Modified: July 15, 2025, 8:06 p.m.

5.4

CVSS3.1

CVE-2025-2950 - IBM i improper HTTP header neutralization

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

πŸ“… Published: April 18, 2025, 2:50 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 4:41 p.m.
Total resulsts: 344963
Page 5296 of 34,497
Β« previous page Β» next page
Filters