9.4

CVSS4.0

CVE-2025-47788 - Missing Path Validation Enables Path Traversal in Controller.php

Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal. v602 contains a fix for …

πŸ“… Published: May 15, 2025, 7:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-46834 - Alchemy's Modular Account can use executeUserOp to bypass allowlist prevalidation hook

Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external parties and would use the…

πŸ“… Published: May 15, 2025, 7:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.9

CVSS4.0

CVE-2025-47786 - Emlog vulnerable to Stored Cross-site Scripting

Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, inducing all website users to click. In `/admin/comment.php`, the parameter `perpage_num` is not validated and is direct…

πŸ“… Published: May 15, 2025, 7:33 p.m. πŸ”„ Last Modified: June 12, 2025, 4:39 p.m.

6.9

CVSS4.0

CVE-2025-4716 - Campcodes Sales and Inventory System credit_transaction_add.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be launched rem…

πŸ“… Published: May 15, 2025, 7:31 p.m. πŸ”„ Last Modified: May 27, 2025, 2:11 p.m.

6.9

CVSS4.0

CVE-2025-4715 - Campcodes Sales and Inventory System view_application.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remote…

πŸ“… Published: May 15, 2025, 7:31 p.m. πŸ”„ Last Modified: May 27, 2025, 2:11 p.m.

8.3

CVSS3.1

CVE-2025-47785 - EMLOG SQL Injection Vulnerability

Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injectio…

πŸ“… Published: May 15, 2025, 7:29 p.m. πŸ”„ Last Modified: June 12, 2025, 4:39 p.m.

8.9

CVSS4.0

CVE-2025-47787 - Emlog Pro Contains a File Upload Vulnerability

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This insufficient validation a…

πŸ“… Published: May 15, 2025, 7:27 p.m. πŸ”„ Last Modified: July 1, 2025, 2:42 p.m.

7.8

CVSS3.1

CVE-2025-47161 - Microsoft Defender for Endpoint Elevation of Privilege Vulnerability

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

πŸ“… Published: May 15, 2025, 7:21 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.6

CVSS4.0

CVE-2025-47784 - Emlog vulnerable to Deserialization of Untrusted Data

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return `false`. Commit 9643250…

πŸ“… Published: May 15, 2025, 7:21 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 5:19 p.m.

7.5

CVSS3.1

CVE-2025-26481 -

Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.

πŸ“… Published: May 15, 2025, 7:03 p.m. πŸ”„ Last Modified: July 11, 2025, 3:56 p.m.
Total resulsts: 349182
Page 5400 of 34,919
Β« previous page Β» next page
Filters