7.7

CVSS4.0

CVE-2025-6031 - Insecure device pairing in end of life Amazon Cloud Cam

Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due to end-of-life statusโ€ฆ

๐Ÿ“… Published: June 12, 2025, 7:29 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-49576 - Citizen allows stored XSS in search no result messages

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability โ€ฆ

๐Ÿ“… Published: June 12, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 6:56 p.m.

6.5

CVSS3.1

CVE-2025-49578 - Citizen allows stored XSS in user registration date message

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editintโ€ฆ

๐Ÿ“… Published: June 12, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 6:48 p.m.

6.5

CVSS3.1

CVE-2025-49579 - Citizen allows stored XSS in menu heading message

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group hasโ€ฆ

๐Ÿ“… Published: June 12, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 6:44 p.m.

6.5

CVSS3.1

CVE-2025-49575 - Citizen allows stored XSS in Command Palette tip messages

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterโ€ฆ

๐Ÿ“… Published: June 12, 2025, 6:45 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 6:59 p.m.

6.5

CVSS3.1

CVE-2025-49577 - Citizen allows stored XSS in preference menu headings

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.

๐Ÿ“… Published: June 12, 2025, 6:45 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 6:52 p.m.

1.7

CVSS4.0

CVE-2025-43866 - Vantage6 Server JWT secret not cryptographically secure

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: June 12, 2025, 6:04 p.m. ๐Ÿ”„ Last Modified: Sept. 17, 2025, 6:44 p.m.

1.7

CVSS4.0

CVE-2025-43863 - vantage6 lacks brute-force protection on change password functionality

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: โ€ฆ

๐Ÿ“… Published: June 12, 2025, 5:29 p.m. ๐Ÿ”„ Last Modified: Sept. 17, 2025, 6:46 p.m.

6.9

CVSS4.0

CVE-2025-49081 - Input validation vulnerability in the Secure Access prior to version 13.55

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrative UI by writing invalid data to the warehouse oveโ€ฆ

๐Ÿ“… Published: June 12, 2025, 5:25 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 8:32 p.m.

8.7

CVSS4.0

CVE-2025-49080 - Memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requiremenโ€ฆ

๐Ÿ“… Published: June 12, 2025, 5:08 p.m. ๐Ÿ”„ Last Modified: June 23, 2025, 2:09 p.m.
Total resulsts: 348435
Page 4967 of 34,844
ยซ previous page ยป next page
Filters