9.3

CVSS3.1

CVE-2025-30223 - Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due to improper HTML escaping of user-controlled data. This vulnerability allows attackers to inject malicious JavaScript code thโ€ฆ

๐Ÿ“… Published: March 31, 2025, 4:17 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 6:58 p.m.

8.4

CVSS4.0

CVE-2025-30161 - OpenEMR Stored XSS in OpenEMR Bronchitis Form

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This vulnerability is fixed iโ€ฆ

๐Ÿ“… Published: March 31, 2025, 4:12 p.m. ๐Ÿ”„ Last Modified: May 13, 2025, 1:36 p.m.

6.4

CVSS3.1

CVE-2025-30149 - OpenEMR Reflected XSS in AJAX Script

OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulnerability is fixed in 7.0.3.

๐Ÿ“… Published: March 31, 2025, 4:07 p.m. ๐Ÿ”„ Last Modified: April 30, 2025, 4:08 p.m.

7.2

CVSS4.0

CVE-2025-29772 - OpenEMR allows Reflected XSS in CAMOS new.php

OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS new.php. This vulnerabiโ€ฆ

๐Ÿ“… Published: March 31, 2025, 4:03 p.m. ๐Ÿ”„ Last Modified: May 13, 2025, 1:36 p.m.

7.5

CVSS4.0

CVE-2025-1449 - Admin Shell Access Vulnerability in Rockwell Automation Verve Asset Manager

A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy Agentless Device Inventory (ADI) capability (deprecated since the 1.36 release) allows users to change a variable with inadโ€ฆ

๐Ÿ“… Published: March 31, 2025, 4 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

6.9

CVSS4.0

CVE-2025-3002 - Digital China DCME-520 mon_merge_stat_hist.php os command injection

A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injeโ€ฆ

๐Ÿ“… Published: March 31, 2025, 4 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

4.3

CVSS3.1

CVE-2025-30155 - Tuleap does not enforce read permissions on parent trackers in the REST API

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.

๐Ÿ“… Published: March 31, 2025, 3:58 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 10:04 p.m.

5.3

CVSS3.1

CVE-2025-30209 - Tuleap has improper permission handling in the REST endpoints and release notes display of the FRS โ€ฆ

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleapโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:53 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 9:59 p.m.

4.8

CVSS3.1

CVE-2025-30203 - Tuleap allows XSS via the content of RSS feeds in the RSS widgets

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:48 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 10:03 p.m.

4.6

CVSS3.1

CVE-2025-29929 - Tuleap is missing CSRF protection on tracker hierarchy administration

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerabโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:40 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 10:07 p.m.
Total resulsts: 343980
Page 5600 of 34,398
ยซ previous page ยป next page
Filters