0.0

CVE-2025-26742 - WordPress Gallery for Social Photo plugin <= 1.0.0.35 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35.

πŸ“… Published: March 25, 2025, 2:37 p.m. πŸ”„ Last Modified: April 1, 2026, 5:18 p.m.

8.2

CVSS3.1

CVE-2025-27147 - GLPI Inventory plugin has Improper Access Control Vulnerability

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerabilit…

πŸ“… Published: March 25, 2025, 2:26 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.6

CVSS4.0

CVE-2025-30212 - Frappe has possibility of SQL injection due to improper validations

Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue. Upgrading is required; no o…

πŸ“… Published: March 25, 2025, 2:21 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 3:52 p.m.

7.8

CVSS3.0

CVE-2025-2532 - Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability

Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious…

πŸ“… Published: March 25, 2025, 2:17 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 5:13 p.m.

7.8

CVSS3.0

CVE-2025-2531 - Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit …

πŸ“… Published: March 25, 2025, 2:17 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 2:04 p.m.

7.8

CVSS3.0

CVE-2025-2530 - Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability

Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must v…

πŸ“… Published: March 25, 2025, 2:16 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 2:12 p.m.

4.8

CVSS4.0

CVE-2024-55604 - Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources

Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions of Appsmith prior to 1.51, app viewers are able to get a li…

πŸ“… Published: March 25, 2025, 2:15 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 6:11 p.m.

7.8

CVSS3.1

CVE-2025-22230 - Authentication bypass vulnerability

VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control.Β A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM.

πŸ“… Published: March 25, 2025, 2:06 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.5

CVSS3.1

CVE-2025-27631 -

The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.

πŸ“… Published: March 25, 2025, 12:46 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

4.1

CVSS3.1

CVE-2025-29932 -

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

πŸ“… Published: March 25, 2025, 12:44 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 10:06 p.m.
Total resulsts: 343923
Page 5692 of 34,393
Β« previous page Β» next page
Filters