6.5

CVSS3.1

CVE-2025-49575 - Citizen allows stored XSS in Command Palette tip messages

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinter…

πŸ“… Published: June 12, 2025, 6:45 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:59 p.m.

6.5

CVSS3.1

CVE-2025-49577 - Citizen allows stored XSS in preference menu headings

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.

πŸ“… Published: June 12, 2025, 6:45 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:52 p.m.

1.7

CVSS4.0

CVE-2025-43866 - Vantage6 Server JWT secret not cryptographically secure

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixe…

πŸ“… Published: June 12, 2025, 6:04 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 6:44 p.m.

1.7

CVSS4.0

CVE-2025-43863 - vantage6 lacks brute-force protection on change password functionality

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: …

πŸ“… Published: June 12, 2025, 5:29 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 6:46 p.m.

6.9

CVSS4.0

CVE-2025-49081 - Input validation vulnerability in the Secure Access prior to version 13.55

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrative UI by writing invalid data to the warehouse ove…

πŸ“… Published: June 12, 2025, 5:25 p.m. πŸ”„ Last Modified: June 17, 2025, 8:32 p.m.

8.7

CVSS4.0

CVE-2025-49080 - Memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requiremen…

πŸ“… Published: June 12, 2025, 5:08 p.m. πŸ”„ Last Modified: June 23, 2025, 2:09 p.m.

3.7

CVSS3.1

CVE-2025-5982 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

πŸ“… Published: June 12, 2025, 4:27 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 1:07 p.m.

7.3

CVSS4.0

CVE-2024-7562 -

A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this issue.

πŸ“… Published: June 12, 2025, 4:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-49467 - Joomla Extension - jevents.net - SQL injection vulnerability in JEvents component before 3.6.88 and…

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

πŸ“… Published: June 12, 2025, 3:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-36573 -

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: June 12, 2025, 3:18 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 7:43 p.m.
Total resulsts: 348441
Page 4968 of 34,845
Β« previous page Β» next page
Filters