6.5

CVSS3.1

CVE-2025-20283 - Cisco Identity Services Engine Authenticated Remote Code Execution Vulnerability

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials cou…

📅 Published: July 16, 2025, 4:16 p.m. 🔄 Last Modified: July 17, 2025, 1:07 p.m.

4.3

CVSS3.1

CVE-2025-20272 - Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Blind SQL Injection Vulne…

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplie…

📅 Published: July 16, 2025, 4:16 p.m. 🔄 Last Modified: July 16, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2025-20274 - Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interf…

📅 Published: July 16, 2025, 4:16 p.m. 🔄 Last Modified: July 17, 2025, 1:07 p.m.

8.7

CVSS4.0

CVE-2025-53943 - VoidBot Open-Source Has Improper Permission Check That Allows Unauthorized Command Execution

VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to exe…

📅 Published: July 16, 2025, 4:07 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-53938 - WeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpoints

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows unauthenticat…

📅 Published: July 16, 2025, 4:04 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

9.4

CVSS4.0

CVE-2025-53937 - WeGIA has SQL Injection (Blind Time-Based) Vulnerability in `cargo` Parameter on `control.php` Endp…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the `/controle/control.php` endpoint, specifically in the `cargo` parameter, of WeGIA prior to version 3.4.5. This vulnerability allows attackers …

📅 Published: July 16, 2025, 4:03 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

6.4

CVSS4.0

CVE-2025-53936 - WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parame…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attack…

📅 Published: July 16, 2025, 4:01 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

6.4

CVSS4.0

CVE-2025-53935 - WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parame…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attack…

📅 Published: July 16, 2025, 4 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

6.4

CVSS4.0

CVE-2025-53934 - WeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'control.php' parameter 'descricao_eme…

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject mali…

📅 Published: July 16, 2025, 3:57 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.

5.4

CVSS3.1

CVE-2025-47053 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation …

📅 Published: July 16, 2025, 3:56 p.m. 🔄 Last Modified: July 16, 2025, 4:15 p.m.
Total resulsts: 302240
Page 7 of 30,224
« previous page » next page
Filters