9.1

CVSS3.1

CVE-2025-26847 -

An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 16, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2025-45820 -

Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php.

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 7:41 p.m.

5.5

CVSS3.1

CVE-2025-37814 - tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT

In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as it turns out, (1) the log…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 9:38 p.m.

6.1

CVSS3.1

CVE-2025-28074 -

phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaSc…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 6:39 p.m.

2

CVSS4.0

CVE-2024-55651 - i-Educar Stored Cross-Site Scripting vulnerability

i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de UsuΓ‘rio) input field. Through this attacker vector…

πŸ“… Published: May 7, 2025, 11:49 p.m. πŸ”„ Last Modified: June 17, 2025, 7:44 p.m.

7.5

CVSS3.1

CVE-2025-46727 - Unbounded-Parameter DoS in Rack::QueryParser

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests wi…

πŸ“… Published: May 7, 2025, 11:07 p.m. πŸ”„ Last Modified: June 17, 2025, 7:44 p.m.

4.2

CVSS3.1

CVE-2025-32441 - Rack session gets restored after deletion

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beg…

πŸ“… Published: May 7, 2025, 11:01 p.m. πŸ”„ Last Modified: June 17, 2025, 7:48 p.m.

6.5

CVSS3.1

CVE-2025-0936 - On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File Trans…

On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TA…

πŸ“… Published: May 7, 2025, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-35939 - Craft CMS stores user-provided content in session files

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '…

πŸ“… Published: May 7, 2025, 10:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.7

CVSS4.0

CVE-2025-41431 - TMM Vulnerability

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

πŸ“… Published: May 7, 2025, 10:04 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 4:25 p.m.
Total resulsts: 349182
Page 5499 of 34,919
Β« previous page Β» next page
Filters