6.3

CVSS4.0

CVE-2025-5320 - gradio-app gradio CORS is_valid_origin privilege escalation

A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to erweiterte Rechte. It is possible to initiate the attack remotely. The com…

📅 Published: May 29, 2025, 1:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-48047 - MICI Network Co. Ltd. NetFax Server Command Injection

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

📅 Published: May 29, 2025, 12:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-48046 - MICI Network Co. Ltd. NetFax Server Disclosure of Stored Passwords in Cleartext

An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.

📅 Published: May 29, 2025, 12:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-48045 - MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure

An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

📅 Published: May 29, 2025, 12:29 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-48388 - FreeScout Has Insufficient Protection Against CRLF-injection

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a string containing special symbols (\r, \n, \…

📅 Published: May 29, 2025, 9:16 a.m. 🔄 Last Modified: July 11, 2025, 3:22 p.m.

4.7

CVSS3.1

CVE-2025-27151 - redis-check-aof may lead to stack overflow and potential RCE

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allo…

📅 Published: May 29, 2025, 9:07 a.m. 🔄 Last Modified: Dec. 23, 2025, 3:03 p.m.

4.9

CVSS3.1

CVE-2024-52588 - Strapi allows Server-Side Request Forgery in Webhook function

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.

📅 Published: May 29, 2025, 9:02 a.m. 🔄 Last Modified: June 24, 2025, 6:27 p.m.

7.2

CVSS4.0

CVE-2025-4687 - Account pre-hijacking through invite misuse

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account a…

📅 Published: May 29, 2025, 8:59 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-5286 - Bold Builder <= 5.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via additional_set…

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo…

📅 Published: May 29, 2025, 8:22 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

6.4

CVSS3.1

CVE-2025-4670 - Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ed…

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user suppl…

📅 Published: May 29, 2025, 8:22 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.
Total resulsts: 347736
Page 5085 of 34,774
« previous page » next page
Filters