9.8

CVSS3.1

CVE-2024-55532 - Apache Ranger: Improper Neutralization of Formula Elements in a CSV File

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.

πŸ“… Published: March 3, 2025, 4:04 p.m. πŸ”„ Last Modified: May 21, 2025, 4:12 p.m.

6.4

CVSS4.0

CVE-2025-27418 - WeGIA contains a Stored Cross-Site Scripting (XSS) in 'adicionar_tipo_atendido.php' via the 'tipo' …

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionar_tipo_atendido.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into…

πŸ“… Published: March 3, 2025, 4:03 p.m. πŸ”„ Last Modified: April 10, 2025, 6:37 p.m.

7.7

CVSS3.1

CVE-2025-0555 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

πŸ“… Published: March 3, 2025, 4:02 p.m. πŸ”„ Last Modified: March 4, 2025, 4:50 p.m.

6.4

CVSS4.0

CVE-2025-27417 - WeGIA Contains a Stored Cross-Site Scripting (XSS) in 'adicionar_status_atendido.php' via the 'stat…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionar_status_atendido.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in…

πŸ“… Published: March 3, 2025, 4:01 p.m. πŸ”„ Last Modified: April 11, 2025, 7:11 p.m.

4.8

CVSS3.1

CVE-2025-27099 - Tuleap allows XSS via the tracker names used in the semantic timeframe deletion message

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this vu…

πŸ“… Published: March 3, 2025, 3:54 p.m. πŸ”„ Last Modified: July 10, 2025, 4:48 p.m.

5.4

CVSS3.1

CVE-2025-27094 - Tuleap allows default values to be cleared from field configuration

Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field, the size attribute fo…

πŸ“… Published: March 3, 2025, 3:51 p.m. πŸ”„ Last Modified: July 10, 2025, 4:59 p.m.

7.5

CVSS3.1

CVE-2025-25185 - GPT Academic allows arbitary file read by tarfile uncompress within softlink

GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. An attacker can create a malicious file as a soft link pointing to a target file, then package this soft link file into a tar.gz file and upload it. Su…

πŸ“… Published: March 3, 2025, 3:33 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

7.5

CVSS3.1

CVE-2024-41771 - IBM Engineering Requirements Management DOORS Next information disclosure

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

πŸ“… Published: March 3, 2025, 3:29 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 1:11 a.m.

7.5

CVSS3.1

CVE-2024-41770 - IBM Engineering Requirements Management DOORS Next information disclosure

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

πŸ“… Published: March 3, 2025, 3:28 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 1:11 a.m.

8.8

CVSS3.1

CVE-2024-43169 - IBM Engineering Requirements Management DOORS Next file download

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code.

πŸ“… Published: March 3, 2025, 3:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 346534
Page 6210 of 34,654
Β« previous page Β» next page
Filters