7.7

CVSS4.0

CVE-2025-57751 - Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupiโ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

8.3

CVSS3.1

CVE-2025-7051 - N-central Syslog Configuration Insecure Direct Object Reference

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.

๐Ÿ“… Published: Aug. 21, 2025, 5:34 p.m. ๐Ÿ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

6.9

CVSS4.0

CVE-2025-57768 - Stored XSS in โ€œhoursโ€ fields when creating or editing an issue, using SQLite database

Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Planned Hours field when creating a new project. When sending a POST request to /issues/new/, the value provided in the Planned Hours โ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 5:20 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 10:07 a.m.

6.9

CVSS4.0

CVE-2025-43754 -

Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows attackers to determine if an account exist in the aโ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 5:10 p.m. ๐Ÿ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

6.5

CVSS3.1

CVE-2025-57765 - WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'pre_cadastro_adotante.php' parameter 'msg_e'

WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the pre_cadastro_adotante.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_e parameter. This vuโ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 5:05 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 9:50 p.m.

6.5

CVSS3.1

CVE-2025-57764 - WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'cargos.php' parameter 'msg_e'

WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the cargos.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_e parameter. This vulnerability is โ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 5:04 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 9:51 p.m.

6.9

CVSS4.0

CVE-2025-9311 - itsourcecode Apartment Management System addfair.php sql injection

A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fair/addfair.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly avaiโ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 9:11 p.m.

4.9

CVSS3.1

CVE-2025-8402 - Nil pointer dereference in bulk import crashes server

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.

๐Ÿ“… Published: Aug. 21, 2025, 5:01 p.m. ๐Ÿ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

4.3

CVSS3.1

CVE-2025-6465 - Path traversal in image upload with preview overwrite

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.

๐Ÿ“… Published: Aug. 21, 2025, 5:01 p.m. ๐Ÿ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

6.4

CVSS4.0

CVE-2025-57763 - Cross-Site Scripting (XSS) Reflected in 'insere_despacho.php' parameter 'sccs'

WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the insere_despacho.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the cpf sccs. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: Aug. 21, 2025, 4:59 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 9:11 p.m.
Total resulsts: 307303
Page 80 of 30,731
ยซ previous page ยป next page
Filters