6.5

CVSS3.1

CVE-2025-53008 - GLPI's MailCollector Receiver is vulnerable to credential exfiltration

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal mail receiver credeโ€ฆ

๐Ÿ“… Published: July 30, 2025, 2:09 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 6:56 p.m.

6.5

CVSS3.1

CVE-2025-52897 - GLPI is vulnerable to XSS and open redirection attacks through planning feature

GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.

๐Ÿ“… Published: July 30, 2025, 2:07 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 6:55 p.m.

3.5

CVSS3.1

CVE-2025-52567 - GLPI has overly permissive URL verification

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided siโ€ฆ

๐Ÿ“… Published: July 30, 2025, 2:07 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 6:54 p.m.

6.9

CVSS4.0

CVE-2025-54572 - Ruby SAML DOS vulnerability with large SAML response

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 foโ€ฆ

๐Ÿ“… Published: July 30, 2025, 2:05 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:42 p.m.

9.1

CVSS3.1

CVE-2025-54430 - dedupe is vulnerable to secret exfiltration via `issue_comment`

dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Before commit 3f61e79, a critical severity vulnerability has been identified within the .github/workflows/benchmark-bot.yml workflow, where a issue_commenโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:42 p.m.

5.3

CVSS3.1

CVE-2025-54425 - Umbraco's Delivery API allows for cached requests to be returned with an invalid API key

Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restricted from public access where an API key must be provided in a header to authorize the request. It's also possible to configure output caching, such tโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:42 p.m.

3.3

CVSS3.1

CVE-2025-54410 - Moby's Firewalld reload removes bridge network isolation

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptaโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1:24 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:42 p.m.

5.1

CVSS4.0

CVE-2025-54388 - Moby's Firewalld reload makes published container ports accessible from remote hosts

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including thoโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1:24 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:42 p.m.

6.9

CVSS4.0

CVE-2025-8326 - code-projects Exam Form Submission delete_s7.php sql injection

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/delete_s7.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1:02 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 8:47 p.m.

5.4

CVSS3.1

CVE-2025-47001 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: July 30, 2025, 1 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 1:12 p.m.
Total resulsts: 304501
Page 79 of 30,451
ยซ previous page ยป next page
Filters