5.3

CVSS4.0

CVE-2025-5013 - HkCms Search index.html cross site scripting

A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack r…

πŸ“… Published: May 21, 2025, 12:31 a.m. πŸ”„ Last Modified: June 17, 2025, 2:10 p.m.

4.8

CVSS4.0

CVE-2025-5011 - moonlightL hexo-boot Dynamic List Page index.html cross site scripting

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has bee…

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:11 p.m.

8.4

CVSS3.1

CVE-2025-27997 -

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 1:52 p.m.

5.5

CVSS3.1

CVE-2024-56428 -

The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 2:10 p.m.

5.5

CVSS3.1

CVE-2025-4057 - Activemq-artemis-operator: amq broker operator starting credentials reuse

A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2024-56429 -

itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-27558 -

IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP …

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-48200 -

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-40775 - DNS message with invalid TSIG causes an assertion failure

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-45755 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improper…

πŸ“… Published: May 21, 2025, midnight πŸ”„ Last Modified: June 10, 2025, 7:34 p.m.
Total resulsts: 345234
Page 4909 of 34,524
Β« previous page Β» next page
Filters