6.6

CVSS4.0

CVE-2025-30217 - Frappe has possibility of SQL injection due to improper validations

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information. Versions 14.93.2 and 15.55.0 contain a patch for the issue. No known wo…

πŸ“… Published: March 26, 2025, 4:18 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 6:04 p.m.

4.1

CVSS3.1

CVE-2025-30164 - Icinga Web 2 has open redirect on login page

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipul…

πŸ“… Published: March 26, 2025, 4:13 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:02 p.m.

1.1

CVSS4.0

CVE-2025-27609 - Icinga Web 2 Vulnerable to Reflected XSS

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on be…

πŸ“… Published: March 26, 2025, 4:10 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:11 p.m.

0.0

CVE-2025-2825 - CrushFTP HTTP Unauthenticated Access

DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.

πŸ“… Published: March 26, 2025, 3:58 p.m. πŸ”„ Last Modified: April 4, 2025, 8:15 p.m.

7.7

CVSS3.1

CVE-2025-27406 - Icinga Reporting Stored XSS leads to SSRF

Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act o…

πŸ“… Published: March 26, 2025, 3:49 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

8.4

CVSS4.0

CVE-2025-2098 - Dylib Hijacking in Fast CAD Reader

Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users…

πŸ“… Published: March 26, 2025, 3:23 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 9:15 a.m.

7.7

CVSS3.1

CVE-2025-27405 - Icinga Web 2 has XSS in embedded content

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that …

πŸ“… Published: March 26, 2025, 3:10 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-26739 - WordPress newseqo theme <= 2.1.1 - Stored Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction newseqo allows Stored XSS.This issue affects newseqo: from n/a through 2.1.1.

πŸ“… Published: March 26, 2025, 2:58 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.5

CVSS3.1

CVE-2025-2820 - Denial of Service

An authenticated attacker can compromise the availability of the device via the network

πŸ“… Published: March 26, 2025, 2:58 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.5

CVSS3.1

CVE-2025-26747 - WordPress RainbowNews theme <= 1.0.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.

πŸ“… Published: March 26, 2025, 2:56 p.m. πŸ”„ Last Modified: July 13, 2025, 11:14 a.m.
Total resulsts: 343183
Page 5601 of 34,319
Β« previous page Β» next page
Filters