6.4

CVSS3.1

CVE-2025-2540 - Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Sโ€ฆ

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wโ€ฆ

๐Ÿ“… Published: July 3, 2025, 11:19 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

4.8

CVSS4.0

CVE-2025-6563 - Cross-site scripting via dst parameter in RouterOS WiFi hotspot

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can alโ€ฆ

๐Ÿ“… Published: July 3, 2025, 11:18 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

8.6

CVSS3.1

CVE-2025-1708 - CVE-2025-1708

The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.

๐Ÿ“… Published: July 3, 2025, 11:18 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

5.2

CVSS4.0

CVE-2025-6587 - Exposure of system environment variables in Docker Desktop diagnostic logs

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.ย  A malicious actor with read access to these logs could obtain secrets and further use theโ€ฆ

๐Ÿ“… Published: July 3, 2025, 10:03 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

1.8

CVSS4.0

CVE-2025-0885 - Incorrect Authorization vulnerability affects OpenTextโ„ข GroupWise

Incorrect Authorization vulnerability in OpenTextโ„ข GroupWise allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow unauthorized access to calendar items marked private. This issue affects GroupWise versions 7 through 17.5, 23.4, 24.1, 24.2, 24.3, 2โ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:54 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

6.4

CVSS3.1

CVE-2024-5647 - Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Sโ€ฆ

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:22 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

0.0

CVE-2025-38173 - crypto: marvell/cesa - Handle zero-length skcipher requests

In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access random memory for zero-length skcipher requests. Just return 0.

๐Ÿ“… Published: July 3, 2025, 8:36 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

0.0

CVE-2025-38171 - power: supply: max77705: Fix workqueue error handling in probe

In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Fix workqueue error handling in probe The create_singlethread_workqueue() doesn't return error pointers, it returns NULL. Also cleanup the workqueue on the error paths.

๐Ÿ“… Published: July 3, 2025, 8:36 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

0.0

CVE-2025-38170 - arm64/fpsimd: Discard stale CPU state when handling SME traps

In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Discard stale CPU state when handling SME traps The logic for handling SME traps manipulates saved FPSIMD/SVE/SME state incorrectly, and a race with preemption can result in a task having TIF_SME set and TIF_FOREIGNโ€ฆ

๐Ÿ“… Published: July 3, 2025, 8:36 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

0.0

CVE-2025-38169 - arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP

In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP On system with SME, a thread's kernel FPSIMD state may be erroneously clobbered during a context switch immediately after that state is restored. Systems without SME โ€ฆ

๐Ÿ“… Published: July 3, 2025, 8:36 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.
Total resulsts: 300244
Page 4 of 30,025
ยซ previous page ยป next page
Filters