7.2

CVSS3.1

CVE-2025-46340 - Misskey CSS Style Injection Vulnerability In `MkUrlPreview`

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the `MkUrlPreview` component. …

📅 Published: May 5, 2025, 6:35 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:47 p.m.

6.9

CVSS4.0

CVE-2025-4283 - SourceCodester/oretnom23 Stock Management System Login.php sql injection

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. Th…

📅 Published: May 5, 2025, 6:31 p.m. 🔄 Last Modified: May 14, 2025, 8:56 p.m.

2.1

CVSS4.0

CVE-2025-46553 - @misskey-dev/summaly Redirect Filter Bypass

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects…

📅 Published: May 5, 2025, 6:28 p.m. 🔄 Last Modified: Dec. 1, 2025, 1:49 p.m.

8.6

CVSS4.0

CVE-2025-46335 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon U…

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of use…

📅 Published: May 5, 2025, 6:23 p.m. 🔄 Last Modified: May 28, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-4279 - External image replace <= 1.0.8 - Authenticated (Contributor+) Arbitrary File Upload

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with contribu…

📅 Published: May 5, 2025, 6:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-43852 - GHSL-2025-022_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , if model_name contains…

📅 Published: May 5, 2025, 6:21 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43851 - GHSL-2025-021_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , a new instance of Audi…

📅 Published: May 5, 2025, 6:21 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43850 - GHSL-2025-020_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load t…

📅 Published: May 5, 2025, 6:20 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43849 - GHSL-2025-019_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge function in process_ckpt.py, which uses them …

📅 Published: May 5, 2025, 6:20 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

9.5

CVSS4.0

CVE-2025-4318 - Input validation issue in AWS Amplify Studio UI component properties

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build pr…

📅 Published: May 5, 2025, 6:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345215
Page 5153 of 34,522
« previous page » next page
Filters