6.5

CVSS3.1

CVE-2025-25510 -

Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 1:36 p.m.

8.4

CVSS4.0

CVE-2025-27088 - Reflected Cross-site Scripting (XSS) in template implementation in oxyno-zeta/s3-proxy

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trustedโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 10:33 p.m. ๐Ÿ”„ Last Modified: May 20, 2025, 4:47 p.m.

5.1

CVSS4.0

CVE-2025-27097 - Cache variables with the operations when transforms exist on the root level even if variables changโ€ฆ

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transfoโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 8:15 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2025, 8:18 p.m.

5.8

CVSS3.1

CVE-2025-27098 - Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTโ€ฆ

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any clieโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 8:13 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2025, 8:18 p.m.

2.3

CVSS4.0

CVE-2025-25299 - Cross-site scripting (XSS) in the real-time collaboration package

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. This vulnerability affects user markers, which represent users' positions within โ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 7:23 p.m. ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.

9.8

CVSS3.1

CVE-2025-24893 - Remote code execution as guest via SolrSearchMacros request in xwiki

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproducโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 7:19 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

8.7

CVSS4.0

CVE-2025-0352 - Rapid Response Monitoring My Security Account App Authorization Bypass Through User-Controlled Key

Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.

๐Ÿ“… Published: Feb. 20, 2025, 7:15 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2025, 8:24 p.m.

9.4

CVSS4.0

CVE-2025-1265 - Elseta Vinci Protocol Analyzer OS Command Injection

An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.

๐Ÿ“… Published: Feb. 20, 2025, 7:11 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2025, 8:52 p.m.

9.4

CVSS4.0

CVE-2025-27096 - SQL Injection endpoint 'html/personalizacao_upload.php' parameter 'id_campo' in WeGIA

WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive infoโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 7:07 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

7

CVSS4.0

CVE-2025-26618 - SSH SFTP packet size not verified properly in Erlang OTP

Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang. Packet sizeโ€ฆ

๐Ÿ“… Published: Feb. 20, 2025, 7:04 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.
Total resulsts: 344032
Page 6155 of 34,404
ยซ previous page ยป next page
Filters