9.1

CVSS3.1

CVE-2025-47933 - Argo CD allows cross-site scripting on repositories page

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross…

πŸ“… Published: May 28, 2025, 2:30 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 2:28 a.m.

7.3

CVSS3.1

CVE-2025-4134 - Lack of file validation in Avast Business Antivirus for Linux allows writing untrusted update files

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.

πŸ“… Published: May 28, 2025, 1:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-48734 - Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by…

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by defaul…

πŸ“… Published: May 28, 2025, 1:32 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

5.1

CVSS4.0

CVE-2025-40651 - Reflected Cross Site Scripting (XSS) in Real Easy Store

Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This vulnerability can be exploited to steal sens…

πŸ“… Published: May 28, 2025, 1:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-5277 -

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.

πŸ“… Published: May 28, 2025, 1:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-4493 -

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :Β  * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devol…

πŸ“… Published: May 28, 2025, 12:35 p.m. πŸ”„ Last Modified: June 25, 2025, 3:48 p.m.

6.9

CVSS4.0

CVE-2025-5299 - SourceCodester Client Database Management System user_order_customer_update.php unrestricted upload

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack…

πŸ“… Published: May 28, 2025, noon πŸ”„ Last Modified: June 10, 2025, 3:46 p.m.

6.9

CVSS4.0

CVE-2025-5298 - Campcodes Online Hospital Management System betweendates-detailsreports.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the …

πŸ“… Published: May 28, 2025, 11:31 a.m. πŸ”„ Last Modified: May 28, 2025, 8:37 p.m.

4.8

CVSS4.0

CVE-2025-5297 - SourceCodester Computer Store System main.c Add stack-based overflow

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has to be approached lo…

πŸ“… Published: May 28, 2025, 11:31 a.m. πŸ”„ Last Modified: June 10, 2025, 7:33 p.m.

2.3

CVSS4.0

CVE-2025-3864 - Connection pool exhaustion in hackney

Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library. Fix for this issue has been included inΒ 1.24.0 release.

πŸ“… Published: May 28, 2025, 11:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345998
Page 4916 of 34,600
Β« previous page Β» next page
Filters