7.5

CVSS3.1

CVE-2025-5115 - MadeYouReset HTTP/2 vulnerability

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consumeโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 7:07 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 7:07 p.m.

5.1

CVSS4.0

CVE-2025-43746 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.โ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 6:37 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-9240 - elunez eladmin info information disclosure

A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file /auth/info. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

๐Ÿ“… Published: Aug. 20, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 6:32 p.m.

6.3

CVSS4.0

CVE-2025-9239 - elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryption

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd lโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 6:02 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-9238 - Swatadru Exam-Seating-Arrangement Student Login student.php sql injection

A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affected is an unknown function of the file /student.php of the component Student Login. Executing manipulation of the argument email can lead to sql injection. It is possible to launโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 6:02 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

9.3

CVSS3.1

CVE-2025-55746 - Directus allows unauthenticated file upload and file modification due to lacking input sanitization

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' dataโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 5:58 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2025-9237 - CodeAstro Ecommerce Website Edit Your Account my_account.php cross site scripting

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the โ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 5:32 p.m.

5.3

CVSS4.0

CVE-2025-9236 - Portabilis i-Diario Tipos de usร rio educar_tipo_usuario_lst.php sql injection

A vulnerability has been found in Portabilis i-Diario up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usร rio Page. Such manipulation of the argument nm_tipo leads to sql injection. The attack may be performed from a remote locโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 5:32 p.m.

5.4

CVSS3.1

CVE-2025-47054 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation โ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 5:08 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 5:08 p.m.

5.4

CVSS3.1

CVE-2025-46849 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: Aug. 20, 2025, 5:06 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 5:06 p.m.
Total resulsts: 306445
Page 6 of 30,645
ยซ previous page ยป next page
Filters