3.1

CVSS3.1

CVE-2025-46720 - Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fielโ€ฆ

Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the existence or value of otherwise unreadable fโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2025, 7:53 p.m.

5.4

CVSS4.0

CVE-2025-46719 - Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading tโ€ฆ

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 8:18 p.m.

5.3

CVSS4.0

CVE-2025-46571 - Open WebUI vulnerable to limited stored XSS vila uploaded html file

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open tโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:45 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 8:18 p.m.

5.4

CVSS3.1

CVE-2024-42212 - HCL BigFix Compliance is affected by an improper or missing SameSite attribute

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

๐Ÿ“… Published: May 5, 2025, 6:40 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 9:04 p.m.

5.4

CVSS3.1

CVE-2025-46559 - Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation allows malicious AiScrโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:38 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 6:29 p.m.

7.2

CVSS3.1

CVE-2025-46340 - Misskey CSS Style Injection Vulnerability In `MkUrlPreview`

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the `MkUrlPreview` component. โ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 6:47 p.m.

6.9

CVSS4.0

CVE-2025-4283 - SourceCodester/oretnom23 Stock Management System Login.php sql injection

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. Thโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: May 14, 2025, 8:56 p.m.

2.1

CVSS4.0

CVE-2025-46553 - @misskey-dev/summaly Redirect Filter Bypass

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirectsโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:28 p.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 1:49 p.m.

8.6

CVSS4.0

CVE-2025-46335 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Uโ€ฆ

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of useโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:23 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-4279 - External image replace <= 1.0.8 - Authenticated (Contributor+) Arbitrary File Upload

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with contribuโ€ฆ

๐Ÿ“… Published: May 5, 2025, 6:22 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 11 p.m.
Total resulsts: 346560
Page 5287 of 34,656
ยซ previous page ยป next page
Filters