5.3

CVSS4.0

CVE-2025-2711 - Yonyou UFIDA ERP-NC systop.jsp cross site scripting

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been discโ€ฆ

๐Ÿ“… Published: March 24, 2025, 9 p.m. ๐Ÿ”„ Last Modified: July 15, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-2710 - Yonyou UFIDA ERP-NC menu.jsp cross site scripting

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation of the argument flag leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the publโ€ฆ

๐Ÿ“… Published: March 24, 2025, 8:31 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 12:27 a.m.

5.3

CVSS4.0

CVE-2025-2709 - Yonyou UFIDA ERP-NC login.jsp cross site scripting

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed โ€ฆ

๐Ÿ“… Published: March 24, 2025, 8 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 12:32 a.m.

7.8

CVSS3.0

CVE-2025-2231 - PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit โ€ฆ

๐Ÿ“… Published: March 24, 2025, 7:45 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 12:49 a.m.

5.3

CVSS4.0

CVE-2025-2708 - zhijiantianya ruoyi-vue-pro Backend File Upload Interface upload path traversal

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface. The manipulation of the argument path leads to path traversal. It is possible to iโ€ฆ

๐Ÿ“… Published: March 24, 2025, 7:31 p.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 2:13 a.m.

5.3

CVSS4.0

CVE-2025-2707 - zhijiantianya ruoyi-vue-pro Front-End Store Interface upload path traversal

A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component Front-End Store Interface. The manipulation of the argument path leads to path traversโ€ฆ

๐Ÿ“… Published: March 24, 2025, 7 p.m. ๐Ÿ”„ Last Modified: July 15, 2025, 1:07 p.m.

3.4

CVSS3.1

CVE-2025-30163 - Node based network policies may incorrectly allow workload traffic

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Noโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6:46 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:51 p.m.

3.2

CVSS3.1

CVE-2025-30162 - East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancโ€ฆ

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6:44 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:50 p.m.

5.3

CVSS4.0

CVE-2025-2706 - Digiwin ERP UploadAjaxAPI.ashx unrestricted upload

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: March 24, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-2748 - Kentico Xperience stored cross-site scripting in multiple-file upload functionality

Theย Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

๐Ÿ“… Published: March 24, 2025, 6:22 p.m. ๐Ÿ”„ Last Modified: Dec. 27, 2025, 5:15 p.m.
Total resulsts: 349182
Page 6232 of 34,919
ยซ previous page ยป next page
Filters