6.5

CVSS3.1

CVE-2025-32795 - Dify Allows Insecure User Role Access Control for APP Editing

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app details, despite be…

πŸ“… Published: April 18, 2025, 4:05 p.m. πŸ”„ Last Modified: June 19, 2025, 12:25 a.m.

8.7

CVSS4.0

CVE-2025-32792 - ses's global contour bindings leak into Compartment lexical scope

SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web extensions using `ses` and the Compartment API to evaluate third-party code in an isolated execution environment that hav…

πŸ“… Published: April 18, 2025, 4:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-32442 - Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass

Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for different content types have a possibility to bypass validation by providing a _slightly altered_ content type such as w…

πŸ“… Published: April 18, 2025, 3:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 9:15 p.m.

8.6

CVSS4.0

CVE-2025-32389 - NamelessMC Vulnerable to SQL Injections in /user/messaging and /panel/users/reports Pages

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a&param[1]=b&…

πŸ“… Published: April 18, 2025, 3:56 p.m. πŸ”„ Last Modified: May 13, 2025, 3:23 p.m.

5.3

CVSS3.1

CVE-2025-31120 - NamelessMC Vulnerable to Cookie-Based View Count Manipulation

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application relies on a client-side cookie (nl-topic-[t…

πŸ“… Published: April 18, 2025, 3:52 p.m. πŸ”„ Last Modified: May 13, 2025, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-31118 - NamelessMC Has Forum Reply Submission Time Limit Bypass

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously post replies without any time restriction, re…

πŸ“… Published: April 18, 2025, 3:52 p.m. πŸ”„ Last Modified: May 13, 2025, 3:27 p.m.

7.3

CVSS3.1

CVE-2025-30357 - NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator de…

πŸ“… Published: April 18, 2025, 3:51 p.m. πŸ”„ Last Modified: May 13, 2025, 3:40 p.m.

7.1

CVSS3.1

CVE-2025-30158 - NamelessMC Forum iframe width/height abuse causing UI-based Denial of Service

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attributes. This allows an authenticated attacker to…

πŸ“… Published: April 18, 2025, 3:50 p.m. πŸ”„ Last Modified: May 13, 2025, 3:40 p.m.

7.5

CVSS3.1

CVE-2025-29784 - NamelessMC Has Lack of Length Validation for s Parameter in GET Requests

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performan…

πŸ“… Published: April 18, 2025, 3:50 p.m. πŸ”„ Last Modified: May 13, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-27599 - Element X Android vulnerable to loading malicious web pages via received intent

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temp…

πŸ“… Published: April 18, 2025, 3:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346717
Page 5471 of 34,672
Β« previous page Β» next page
Filters