6.5

CVSS3.1

CVE-2025-28367 -

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 22, 2025, 1:05 p.m.

6.8

CVSS3.1

CVE-2025-43972 -

An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: May 8, 2025, 3:54 p.m.

9.8

CVSS3.1

CVE-2025-29287 -

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 4:37 p.m.

8.1

CVSS3.1

CVE-2025-43922 -

The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-28099 -

opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 3:18 p.m.

6.1

CVSS3.1

CVE-2025-28102 -

A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 1:09 p.m.

9.1

CVSS3.1

CVE-2025-28104 -

Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 3:49 p.m.

2.5

CVSS3.1

CVE-2025-32408 -

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-43971 -

An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: May 8, 2025, 3:57 p.m.

6.4

CVSS3.1

CVE-2025-28103 -

Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

๐Ÿ“… Published: April 21, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 3:49 p.m.
Total resulsts: 346556
Page 5446 of 34,656
ยซ previous page ยป next page
Filters