6

CVSS4.0

CVE-2025-32395 - Vite has an `server.fs.deny` bypass with an invalid `request-target`

Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) does not allow # in request-target. Although an attacker can s…

πŸ“… Published: April 10, 2025, 1:25 p.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

5.4

CVSS3.1

CVE-2023-42007 - IBM Sterling Control Center cross-site scripting

IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 10, 2025, 1:24 p.m. πŸ”„ Last Modified: Aug. 17, 2025, 12:09 a.m.

6.5

CVSS3.1

CVE-2023-43037 - IBM Maximo Application Suite improper access control

IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

πŸ“… Published: April 10, 2025, 1:19 p.m. πŸ”„ Last Modified: Aug. 16, 2025, 11:43 p.m.

6.4

CVSS3.1

CVE-2025-32391 - HedgeDoc allows XSS possibility through malicious SVG uploads

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of XSS when opened in a new tab instead of the editor itself. The XSS is possible by exploiting the JSONP capabilities of GitHub Gi…

πŸ“… Published: April 10, 2025, 1:11 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 6:24 p.m.

4.3

CVSS3.1

CVE-2025-32383 - MaxKB has a reverse shell vulnerability in function library

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privilegedβ€Œ users to create a reverse shell…

πŸ“… Published: April 10, 2025, 1:07 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 9:10 p.m.

6.3

CVSS3.1

CVE-2024-11129 - Generation of Error Message Containing Sensitive Information in GitLab

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

πŸ“… Published: April 10, 2025, 1:02 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:43 p.m.

5.4

CVSS3.1

CVE-2025-30148 - Silverstripe Framework has a XSS vulnerability in HTML editor

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payloa…

πŸ“… Published: April 10, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 5:13 p.m.

5.4

CVSS3.1

CVE-2025-25197 - Silverstripe Elemental enables XSS attacks in elemental "Content blocks in use" reports

Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is …

πŸ“… Published: April 10, 2025, 12:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-1677 - Allocation of Resources Without Limits or Throttling in GitLab

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

πŸ“… Published: April 10, 2025, 12:30 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:38 p.m.

5.3

CVSS3.1

CVE-2025-2408 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

πŸ“… Published: April 10, 2025, 12:30 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:37 p.m.
Total resulsts: 345248
Page 5523 of 34,525
Β« previous page Β» next page
Filters