7.8

CVSS3.1

CVE-2025-25187 - Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Conten…

📅 Published: Feb. 7, 2025, 10:38 p.m. 🔄 Last Modified: April 11, 2025, 6:56 p.m.

5.1

CVSS4.0

CVE-2025-1114 - newbee-mall Add Category Page save cross site scripting

A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack remotely…

📅 Published: Feb. 7, 2025, 10:31 p.m. 🔄 Last Modified: June 20, 2025, 5 p.m.

7.8

CVSS3.1

CVE-2025-24028 - Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text …

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 1:57 a.m.

3.3

CVSS3.1

CVE-2024-55630 - DOM Clobbering leads to temporary DOS in the note viewer in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that…

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 2:10 a.m.

5.3

CVSS4.0

CVE-2025-1113 - taisan tarzan-cms Add Theme admin#themes upload deserialization

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been discl…

📅 Published: Feb. 7, 2025, 9:31 p.m. 🔄 Last Modified: Aug. 21, 2025, 8:29 p.m.

7.5

CVSS3.1

CVE-2025-24366 - Insufficient sanitization of user provided rsync command in SFTPGo

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default commands some optional commands can be activated, one of them being `rsync`. It is disabled in the default configuration and it is limited to the l…

📅 Published: Feb. 7, 2025, 9:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-24980 - Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.…

📅 Published: Feb. 7, 2025, 7:56 p.m. 🔄 Last Modified: Jan. 16, 2026, 6:16 p.m.

5.3

CVSS4.0

CVE-2021-41528 - Improper authorization related to Import / Export interfaces on RISC Platform

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

📅 Published: Feb. 7, 2025, 7:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2021-41527 - 2FA bypass on the RISC Platform

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

📅 Published: Feb. 7, 2025, 7:44 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1106 - CmsEasy database_admin.php restore_action path traversal

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed t…

📅 Published: Feb. 7, 2025, 6:31 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.
Total resulsts: 347987
Page 6694 of 34,799
« previous page » next page
Filters