4.3

CVSS3.1

CVE-2024-25132 - Openshift-dedicated: hive: hibernation controller denial of service

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a …

πŸ“… Published: March 19, 2025, 5:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.9

CVSS4.0

CVE-2025-29926 - The WikiManager REST API allows any user to create wikis

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by …

πŸ“… Published: March 19, 2025, 5:40 p.m. πŸ”„ Last Modified: May 13, 2025, 1:34 p.m.

8.7

CVSS4.0

CVE-2025-29925 - XWiki allows unregistered users to access private pages information through REST endpoint

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent …

πŸ“… Published: March 19, 2025, 5:36 p.m. πŸ”„ Last Modified: April 30, 2025, 3:57 p.m.

8.7

CVSS4.0

CVE-2025-29924 - XWiki uses the wrong wiki reference in AuthorizationManager

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent unregistered users to view pages". The vulnerabilit…

πŸ“… Published: March 19, 2025, 5:31 p.m. πŸ”„ Last Modified: April 30, 2025, 3:58 p.m.

0.0

CVE-2025-2535 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 19, 2025, 5:30 p.m. πŸ”„ Last Modified: March 25, 2026, 10:19 p.m.

5.8

CVSS3.1

CVE-2025-0431 - Enterprise Protection Backslash URL Rewrite Bypass

Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of …

πŸ“… Published: March 19, 2025, 4:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-53967 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged a…

πŸ“… Published: March 19, 2025, 4:10 p.m. πŸ”„ Last Modified: April 14, 2025, 2:58 p.m.

5.4

CVSS3.1

CVE-2024-53968 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged a…

πŸ“… Published: March 19, 2025, 4:10 p.m. πŸ”„ Last Modified: April 14, 2025, 2:57 p.m.

5.4

CVSS3.1

CVE-2024-53969 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged a…

πŸ“… Published: March 19, 2025, 4:09 p.m. πŸ”„ Last Modified: April 14, 2025, 2:56 p.m.

5.4

CVSS3.1

CVE-2024-53970 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: March 19, 2025, 4:09 p.m. πŸ”„ Last Modified: April 14, 2025, 2:55 p.m.
Total resulsts: 349182
Page 6303 of 34,919
Β« previous page Β» next page
Filters