5.1

CVSS4.0

CVE-2023-53906 - ProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load …

📅 Published: Dec. 17, 2025, 10:44 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:44 p.m.

6.2

CVSS4.0

CVE-2023-53905 - ProjectSend r1605 CSV Injection via User Account Export Functionality

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

📅 Published: Dec. 17, 2025, 10:44 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53904 - Xenforo 2.2.13 Authenticated Stored Cross-Site Scripting via Smilie Categories

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, pote…

📅 Published: Dec. 17, 2025, 10:44 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:44 p.m.

7.6

CVSS3.1

CVE-2025-66029 - Open OnDemand affected by Apache proxy passing sensitive headers

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it…

📅 Published: Dec. 17, 2025, 10:32 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:32 p.m.

6.9

CVSS4.0

CVE-2025-14833 - code-projects Online Appointment Booking System deletemanagerclinic.php sql injection

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing manipulation of the argument clinic results in sql injection. The attack can be initiated remotely. The expl…

📅 Published: Dec. 17, 2025, 10:32 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:32 p.m.

7.3

CVSS3.1

CVE-2025-68429 - Storybook manager bundle may expose environment variables during build

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could…

📅 Published: Dec. 17, 2025, 10:26 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:07 p.m.

8.8

CVSS3.1

CVE-2025-68434 - opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator…

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protectio…

📅 Published: Dec. 17, 2025, 10:20 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:20 p.m.

8.1

CVSS3.1

CVE-2025-68147 - opensourcepos has a Cross-site Scripting vulnerability

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration field. The application d…

📅 Published: Dec. 17, 2025, 10:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:16 p.m.

6.4

CVSS4.0

CVE-2025-68145 - mcp-server-git has missing path validation when using --repository flag

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to…

📅 Published: Dec. 17, 2025, 10:12 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:12 p.m.

6.3

CVSS4.0

CVE-2025-68144 - mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local f…

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git r…

📅 Published: Dec. 17, 2025, 10:10 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:10 p.m.
Total resulsts: 323513
Page 58 of 32,352
« previous page » next page
Filters