8.2

CVSS3.1

CVE-2025-27500 - Cross Site Scripting potential in Ziti Console

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This endpoint accepts an HTTP POST to upload a file which is then stored on the node and is available via URL…

πŸ“… Published: March 3, 2025, 6:30 p.m. πŸ”„ Last Modified: March 5, 2025, 8:16 p.m.

6.4

CVSS4.0

CVE-2025-27499 - WeGIA has a stored Cross-Site Scripting (XSS) in 'processa_edicao_socio.php' via the 'socio_nome' p…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into t…

πŸ“… Published: March 3, 2025, 6:23 p.m. πŸ”„ Last Modified: March 6, 2025, 12:21 p.m.

5.3

CVSS3.1

CVE-2024-30154 - HCL SX is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

πŸ“… Published: March 3, 2025, 6:10 p.m. πŸ”„ Last Modified: July 3, 2025, 4:01 p.m.

6.9

CVSS4.0

CVE-2025-1876 - D-Link DAP-1562 HTTP Header http_request_parse stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the function http_request_parse of the component HTTP Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack may be launched …

πŸ“… Published: March 3, 2025, 5 p.m. πŸ”„ Last Modified: May 21, 2025, 4:17 p.m.

5.6

CVSS4.0

CVE-2025-27498 - AEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failure

aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is because in decrypt_inplace in asconcore.rs, tag verification causes an error to be returned with the plaint…

πŸ“… Published: March 3, 2025, 4:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-25303 - Server-Side Request Forgery (SSRF) in MouseTooltipTranslator

The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses the URL parameter from the current URL as the file to download and display to the extension user. Bec…

πŸ“… Published: March 3, 2025, 4:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-25302 - Rembg CORS misconfiguration

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credential…

πŸ“… Published: March 3, 2025, 4:40 p.m. πŸ”„ Last Modified: March 21, 2025, 1:35 p.m.

6.9

CVSS4.0

CVE-2025-25301 - Rembg allows SSRF via /api/remove

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg serv…

πŸ“… Published: March 3, 2025, 4:36 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-27423 - Improper Input Validation in Vim

Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor position, however the i…

πŸ“… Published: March 3, 2025, 4:30 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 6:20 p.m.

7.5

CVSS3.1

CVE-2025-27422 - FACTION Allows Authentication Bypass via User Creation

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure passwor…

πŸ“… Published: March 3, 2025, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6473 of 34,919
Β« previous page Β» next page
Filters