5.1

CVSS4.0

CVE-2025-9233 - Scada-LTS view_edit.shtm cross site scripting

A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation of the argument Name leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be u…

πŸ“… Published: Aug. 20, 2025, 3:32 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

8.7

CVSS4.0

CVE-2009-10005 - ContentKeeper Web Appliance < 125.10 Arbitrary File Access via mimencode

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output …

πŸ“… Published: Aug. 20, 2025, 3:31 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

5.1

CVSS4.0

CVE-2025-55751 - OnboardLite Open Redirect Endpoint

OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, cre…

πŸ“… Published: Aug. 20, 2025, 3:31 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

8.4

CVSS4.0

CVE-2011-10027 - AOL Desktop 9.6 RTX Stack-Based Buffer Overflow

AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows remote attackers to e…

πŸ“… Published: Aug. 20, 2025, 3:31 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

8.7

CVSS4.0

CVE-2025-55732 - Frappe has the possibility of SQL Injection due to improper validations

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the official patch released for CVE-2025-52895.…

πŸ“… Published: Aug. 20, 2025, 3:22 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

6.3

CVSS4.0

CVE-2025-55731 - Frappe has the possibility of Authenticated SQL Injection due to improper validations

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.

πŸ“… Published: Aug. 20, 2025, 3:22 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

5.4

CVSS3.1

CVE-2025-1142 - IBM Edge Application Manager server-side request forgery

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: Aug. 20, 2025, 2:44 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

6.1

CVSS3.1

CVE-2025-1139 - IBM Edge Application Manager incorrect permissions

IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment.

πŸ“… Published: Aug. 20, 2025, 2:42 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

6.5

CVSS3.1

CVE-2025-36114 - IBM QRadar SOAR Plugin App path traversal

IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

πŸ“… Published: Aug. 20, 2025, 2:37 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

7.1

CVSS4.0

CVE-2025-43748 -

Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attac…

πŸ“… Published: Aug. 20, 2025, 2:28 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.
Total resulsts: 307090
Page 75 of 30,709
Β« previous page Β» next page
Filters