4.7

CVSS4.0

CVE-2025-6785 - Tesla Model 3 Physical CAN Bus Injection

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). …

📅 Published: Sept. 4, 2025, 2:13 p.m. 🔄 Last Modified: Sept. 5, 2025, 2:02 p.m.

5.5

CVSS4.0

CVE-2025-8311 -

dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, whic…

📅 Published: Sept. 4, 2025, 2:12 p.m. 🔄 Last Modified: Sept. 5, 2025, 2:02 p.m.

8.4

CVSS3.1

CVE-2025-7388 - Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property…

📅 Published: Sept. 4, 2025, 1:01 p.m. 🔄 Last Modified: Sept. 5, 2025, 2:02 p.m.

9.3

CVSS4.0

CVE-2025-7385 - SQL Injection in GOV CMS

Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.

📅 Published: Sept. 4, 2025, 12:05 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

4.8

CVSS4.0

CVE-2025-41063 - Reflected Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.

📅 Published: Sept. 4, 2025, 11:16 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

4.8

CVSS4.0

CVE-2025-41062 - Reflected Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

📅 Published: Sept. 4, 2025, 11:16 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41061 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/uploadify.

📅 Published: Sept. 4, 2025, 11:15 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41060 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tree.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41059 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tablesorter.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.

5.1

CVSS4.0

CVE-2025-41058 - Stored Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/row_manager.

📅 Published: Sept. 4, 2025, 11:14 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:51 p.m.
Total resulsts: 309087
Page 91 of 30,909
« previous page » next page
Filters