8.8

CVSS3.1

CVE-2025-25614 -

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 6:35 p.m.

6

CVSS3.1

CVE-2024-57492 -

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 6:58 p.m.

9.8

CVSS3.1

CVE-2025-25977 - canvg: Prototype Pollution Vulneralbility

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 4:53 p.m.

5.4

CVSS3.1

CVE-2025-25908 -

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:13 p.m.

8

CVSS3.1

CVE-2025-27910 -

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 7:34 p.m.

8.5

CVSS3.1

CVE-2025-27925 -

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 8:05 p.m.

5.4

CVSS3.1

CVE-2024-53307 -

A reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:08 p.m.

5.4

CVSS3.1

CVE-2025-27924 -

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:03 p.m.

4.8

CVSS4.0

CVE-2025-2133 - ftcms edit cross site scripting

A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/index.php/news/edit. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclo…

πŸ“… Published: March 9, 2025, 11:31 p.m. πŸ”„ Last Modified: March 11, 2025, 8:22 p.m.

5.1

CVSS4.0

CVE-2025-2132 - ftcms Search ajax_all_lists sql injection

A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: March 9, 2025, 11 p.m. πŸ”„ Last Modified: March 11, 2025, 8:25 p.m.
Total resulsts: 343919
Page 5881 of 34,392
Β« previous page Β» next page
Filters