8.1

CVSS3.1

CVE-2025-2160 -

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

📅 Published: April 14, 2025, 2:16 p.m. 🔄 Last Modified: Oct. 30, 2025, 7:01 p.m.

5.3

CVSS4.0

CVE-2025-3569 - JamesZBL/code-projects db-hospital-drug ShiroConfig.java improper authorization

A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclos…

📅 Published: April 14, 2025, 2 p.m. 🔄 Last Modified: Feb. 10, 2026, 9:12 p.m.

5.1

CVSS4.0

CVE-2025-3568 - Webkul Krayin CRM SVG File edit cross site scripting

A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be laun…

📅 Published: April 14, 2025, 1:31 p.m. 🔄 Last Modified: June 26, 2025, 7:21 p.m.

5.3

CVSS4.0

CVE-2025-3567 - veal98 小牛肉 Echo 开源社区系统 Ticket LoginTicketInterceptor.java preHandle improper authorization

A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function preHandle of the file src/main/java/com/greate/community/controller/interceptor/LoginTicketInterceptor.java of the component Ticket Handler. The manipulation leads to improper aut…

📅 Published: April 14, 2025, 1 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-3566 - veal98 小牛肉 Echo 开源社区系统 uploadMdPic unrestricted upload

A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-image-file leads to unrestricted upload. The attack may be initiated remotely. The…

📅 Published: April 14, 2025, 12:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2024-49709 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attacker with an access to user's browser might set such a cookie, wait until the user logs in and then use the same cookie to take over the account. Moreover, the system does not dest…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:07 p.m.

5.1

CVSS4.0

CVE-2024-49708 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for setting delivery address with a malicious script, what causes the script to run in user's context.  This vulnerability…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:08 p.m.

5.1

CVSS4.0

CVE-2024-49707 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for resetting user's password with a malicious script, what causes the script to run in user's context.  This vulnerabi…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:09 p.m.

5.1

CVSS4.0

CVE-2024-49706 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:10 p.m.

5.3

CVSS4.0

CVE-2024-49705 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not be accepted as the server returns an error messa…

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.
Total resulsts: 346636
Page 5638 of 34,664
« previous page » next page
Filters