9.3

CVSS3.1

CVE-2025-55746 - Directus allows unauthenticated file upload and file modification due to lacking input sanitization

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' data…

📅 Published: Aug. 20, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 20, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2025-9237 - CodeAstro Ecommerce Website Edit Your Account my_account.php cross site scripting

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the …

📅 Published: Aug. 20, 2025, 5:32 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:32 p.m.

5.3

CVSS4.0

CVE-2025-9236 - Portabilis i-Diario Tipos de usàrio educar_tipo_usuario_lst.php sql injection

A vulnerability has been found in Portabilis i-Diario up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usàrio Page. Such manipulation of the argument nm_tipo leads to sql injection. The attack may be performed from a remote loc…

📅 Published: Aug. 20, 2025, 5:32 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:32 p.m.

5.4

CVSS3.1

CVE-2025-47054 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation …

📅 Published: Aug. 20, 2025, 5:08 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:08 p.m.

5.4

CVSS3.1

CVE-2025-46849 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Aug. 20, 2025, 5:06 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:06 p.m.

5.4

CVSS3.1

CVE-2025-46852 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Aug. 20, 2025, 5:03 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:03 p.m.

5.1

CVSS4.0

CVE-2025-9235 - Scada-LTS compound_events.shtm cross site scripting

A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.

📅 Published: Aug. 20, 2025, 5:02 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:02 p.m.

5.1

CVSS4.0

CVE-2025-9234 - Scada-LTS maintenance_events.shtm cross site scripting

A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

📅 Published: Aug. 20, 2025, 5:02 p.m. 🔄 Last Modified: Aug. 20, 2025, 5:02 p.m.

5.4

CVSS3.1

CVE-2025-46856 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation …

📅 Published: Aug. 20, 2025, 4:58 p.m. 🔄 Last Modified: Aug. 20, 2025, 4:58 p.m.

5.4

CVSS3.1

CVE-2025-46932 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Aug. 20, 2025, 4:56 p.m. 🔄 Last Modified: Aug. 20, 2025, 4:56 p.m.
Total resulsts: 307170
Page 78 of 30,717
« previous page » next page
Filters