7.6

CVSS3.1

CVE-2025-46619 -

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:26 p.m.

9.8

CVSS3.1

CVE-2025-45017 -

A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: May 9, 2025, 1:44 p.m.

8.6

CVSS3.1

CVE-2025-29906 - Finit bundled getty can bypass /bin/login

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4…

πŸ“… Published: April 29, 2025, 10:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-46552 - KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses wit…

πŸ“… Published: April 29, 2025, 10:13 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS4.0

CVE-2025-46344 - Auth0 NextJS SDK v4 Missing Session Invalidation

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While…

πŸ“… Published: April 29, 2025, 8:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-46550 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious li…

πŸ“… Published: April 29, 2025, 8:41 p.m. πŸ”„ Last Modified: May 9, 2025, 1:59 p.m.

4.3

CVSS3.1

CVE-2025-46549 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability ma…

πŸ“… Published: April 29, 2025, 8:40 p.m. πŸ”„ Last Modified: May 9, 2025, 1:59 p.m.

10

CVSS3.1

CVE-2025-46348 - YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and download an archive without being authenticated. …

πŸ“… Published: April 29, 2025, 8:39 p.m. πŸ”„ Last Modified: May 9, 2025, 1:58 p.m.

5.3

CVSS4.0

CVE-2025-4078 - Wangshen SecGate 3600 g=log_export_file path traversal

A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has be…

πŸ“… Published: April 29, 2025, 8:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-0520 - ShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

πŸ“… Published: April 29, 2025, 7:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347586
Page 5472 of 34,759
Β« previous page Β» next page
Filters