8.5

CVSS3.1

CVE-2025-27925 -

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 8:05 p.m.

8

CVSS3.1

CVE-2025-27910 -

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 7:34 p.m.

9.8

CVSS3.1

CVE-2025-25940 -

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 8:05 p.m.

5.4

CVSS3.1

CVE-2025-27924 -

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 9:03 p.m.

4.3

CVSS3.1

CVE-2025-27926 -

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 8:05 p.m.

5.4

CVSS3.1

CVE-2025-25908 -

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 8:13 p.m.

8.8

CVSS3.1

CVE-2025-25907 -

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 6:13 p.m.

6

CVSS3.1

CVE-2024-57492 -

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: March 24, 2025, 6:58 p.m.

5.4

CVSS3.1

CVE-2024-55199 -

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 8:10 p.m.

9.8

CVSS3.1

CVE-2025-25977 - canvg: Prototype Pollution Vulneralbility

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

๐Ÿ“… Published: March 10, 2025, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 4:53 p.m.
Total resulsts: 349182
Page 6407 of 34,919
ยซ previous page ยป next page
Filters