8.1

CVSS3.1

CVE-2025-6505 -

Unauthorized access and impersonation can occur in versionsย 4.6.2.3226ย and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access. ย Whenโ€ฆ

๐Ÿ“… Published: July 29, 2025, 12:56 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:15 p.m.

8.4

CVSS3.1

CVE-2025-6504 - Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.ย  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could โ€ฆ

๐Ÿ“… Published: July 29, 2025, 12:56 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-54422 - Sandboxie exposes encrypted sandbox key during password change

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, expoโ€ฆ

๐Ÿ“… Published: July 29, 2025, 12:47 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-7458 - SQLite integer overflow in key info allocation may lead to information disclosure.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a laโ€ฆ

๐Ÿ“… Published: July 29, 2025, 12:43 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

5.4

CVSS3.1

CVE-2025-6060 - XSS in DECE Software's Geodi

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before GEODI Setup 9.0.146.

๐Ÿ“… Published: July 29, 2025, 12:25 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

4.4

CVSS3.1

CVE-2025-41241 - Denial-of-service vulnerability

VMware vCenter contains a denial-of-service vulnerability.ย A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.

๐Ÿ“… Published: July 29, 2025, 12:25 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

7.2

CVSS3.1

CVE-2025-6175 - CRLF Injection in DECE Software's Geodi

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting.This issue affects Geodi: before GEODI Setup 9.0.146.

๐Ÿ“… Published: July 29, 2025, 12:22 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

4.8

CVSS4.0

CVE-2025-40686 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'employeeid' parameter in/detailview.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

4.8

CVSS4.0

CVE-2025-40685 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searcstate' parameter in/state.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.

4.8

CVSS4.0

CVE-2025-40684 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searccountry' parameter in/country.php.

๐Ÿ“… Published: July 29, 2025, 12:12 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 2:14 p.m.
Total resulsts: 303533
Page 1 of 30,354
ยป next page
Filters