6.9

CVSS4.0

CVE-2025-2705 - Digiwin ERP FileUploadApi.ashx DoWebUpload unrestricted upload

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclos…

πŸ“… Published: March 24, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-23204 - GraphQl securityAfterResolver not called

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when th…

πŸ“… Published: March 24, 2025, 3:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS3.1

CVE-2023-25610 -

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, versio…

πŸ“… Published: March 24, 2025, 3:39 p.m. πŸ”„ Last Modified: July 24, 2025, 7:56 p.m.

6.9

CVSS3.1

CVE-2021-26091 -

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their …

πŸ“… Published: March 24, 2025, 3:37 p.m. πŸ”„ Last Modified: July 23, 2025, 3:53 p.m.

4.3

CVSS3.1

CVE-2025-0256 - HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure

HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.

πŸ“… Published: March 24, 2025, 3:35 p.m. πŸ”„ Last Modified: April 11, 2025, 5:38 p.m.

6.4

CVSS3.1

CVE-2021-26105 -

A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.

πŸ“… Published: March 24, 2025, 3:27 p.m. πŸ”„ Last Modified: July 24, 2025, 7:18 p.m.

6.5

CVSS3.1

CVE-2025-1558 - Denial of Service Via Malicious GIF

Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.

πŸ“… Published: March 24, 2025, 3:01 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 7:14 p.m.

5.9

CVSS3.1

CVE-2025-30623 - WordPress wA11y – The Web Accessibility Toolbox plugin <= 1.0.3 - Cross Site Scripting (XSS) vulner…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry wA11y – The Web Accessibility Toolbox wa11y allows Stored XSS.This issue affects wA11y – The Web Accessibility Toolbox: from n/a through <= 1.0.3.

πŸ“… Published: March 24, 2025, 1:47 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-30621 - WordPress Translator plugin <= 0.3 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator translator allows Stored XSS.This issue affects Translator: from n/a through <= 0.3.

πŸ“… Published: March 24, 2025, 1:47 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-30620 - WordPress WP Odoo Form Integrator plugin <=1.1.0 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator wp-odoo-form-integrator allows Stored XSS.This issue affects WP Odoo Form Integrator: from n/a through <= 1.1.0.

πŸ“… Published: March 24, 2025, 1:47 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.
Total resulsts: 348413
Page 6157 of 34,842
Β« previous page Β» next page
Filters