7.3

CVSS3.1

CVE-2025-1068 - There is a code injection vulnerability in Esri ArcGIS AllSource

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the …

πŸ“… Published: Feb. 25, 2025, 4:26 p.m. πŸ”„ Last Modified: June 20, 2025, 7:48 p.m.

7.3

CVSS3.1

CVE-2025-1067 - There is a code injection vulnerability in ArcGIS Pro

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4Β that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file …

πŸ“… Published: Feb. 25, 2025, 4:26 p.m. πŸ”„ Last Modified: June 20, 2025, 7:48 p.m.

6.9

CVSS4.0

CVE-2025-23024 - GLPI: Plugins are disabled accessing one page

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

πŸ“… Published: Feb. 25, 2025, 3:47 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-21627 - GLPI Cross-site Scripting vulnerability

GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains…

πŸ“… Published: Feb. 25, 2025, 3:43 p.m. πŸ”„ Last Modified: July 13, 2025, 11:07 a.m.

5.8

CVSS3.1

CVE-2025-21626 - GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.…

πŸ“… Published: Feb. 25, 2025, 3:37 p.m. πŸ”„ Last Modified: March 4, 2025, 1:49 p.m.

5.3

CVSS4.0

CVE-2024-11955 - GLPI index.php redirect

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclo…

πŸ“… Published: Feb. 25, 2025, 3:07 p.m. πŸ”„ Last Modified: March 4, 2025, 1:49 p.m.

10

CVSS3.1

CVE-2023-25574 - JupyterHub's LTI13Authenticator: JWT signature not validated

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only…

πŸ“… Published: Feb. 25, 2025, 2:42 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 9:36 p.m.

5.4

CVSS3.1

CVE-2025-26995 - WordPress Market Exporter plugin <= 2.0.21 - Broken Access Control vulnerability

Missing Authorization vulnerability in Anton Vanyukov Market Exporter market-exporter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Market Exporter: from n/a through <= 2.0.21.

πŸ“… Published: Feb. 25, 2025, 2:17 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-26993 - WordPress Visual Website Collaboration Atarim plugin <= 4.1.0 - Reflected Cross Site Scripting (XS…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Reflected XSS.This issue affects Atarim: from n/a through <= 4.1.0.

πŸ“… Published: Feb. 25, 2025, 2:17 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-26991 - WordPress WPPizza plugin <= 3.19.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ollybach WPPizza wppizza allows Reflected XSS.This issue affects WPPizza: from n/a through <= 3.19.4.

πŸ“… Published: Feb. 25, 2025, 2:17 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.
Total resulsts: 349182
Page 6632 of 34,919
Β« previous page Β» next page
Filters