7.3

CVSS4.0

CVE-2025-46731 - Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work.…

📅 Published: May 5, 2025, 7:35 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:06 p.m.

6.8

CVSS3.1

CVE-2025-46730 - Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external ve…

📅 Published: May 5, 2025, 7:32 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:18 p.m.

5.1

CVSS4.0

CVE-2025-4286 - Intelbras InControl Dispositivos Edição Page credentials storage

A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected storage of credentials. It is possible to laun…

📅 Published: May 5, 2025, 7:31 p.m. 🔄 Last Modified: Aug. 20, 2025, 2:29 a.m.

7.8

CVSS4.0

CVE-2025-46726 - Langroid Vulnerable to XXE Injection via XMLToolMessage

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes th…

📅 Published: May 5, 2025, 7:21 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:28 p.m.

5.3

CVSS3.1

CVE-2024-42213 - HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

📅 Published: May 5, 2025, 7 p.m. 🔄 Last Modified: June 17, 2025, 9:04 p.m.

3.1

CVSS3.1

CVE-2025-46720 - Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fiel…

Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the existence or value of otherwise unreadable f…

📅 Published: May 5, 2025, 6:53 p.m. 🔄 Last Modified: Sept. 19, 2025, 7:53 p.m.

5.4

CVSS4.0

CVE-2025-46719 - Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading t…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be execut…

📅 Published: May 5, 2025, 6:50 p.m. 🔄 Last Modified: June 17, 2025, 8:18 p.m.

5.3

CVSS4.0

CVE-2025-46571 - Open WebUI vulnerable to limited stored XSS vila uploaded html file

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open t…

📅 Published: May 5, 2025, 6:45 p.m. 🔄 Last Modified: June 17, 2025, 8:18 p.m.

5.4

CVSS3.1

CVE-2024-42212 - HCL BigFix Compliance is affected by an improper or missing SameSite attribute

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

📅 Published: May 5, 2025, 6:40 p.m. 🔄 Last Modified: June 17, 2025, 9:04 p.m.

5.4

CVSS3.1

CVE-2025-46559 - Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation allows malicious AiScr…

📅 Published: May 5, 2025, 6:38 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:29 p.m.
Total resulsts: 346555
Page 5286 of 34,656
« previous page » next page
Filters