6.5

CVSS3.1

CVE-2025-23078 - XSS in BreadCrumbs2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X befor…

📅 Published: Jan. 10, 2025, 5:57 p.m. 🔄 Last Modified: Jan. 13, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2024-6880 - CSRF in MegaBIP

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt fu…

📅 Published: Jan. 10, 2025, 5:51 p.m. 🔄 Last Modified: July 12, 2025, 10:23 p.m.

8.7

CVSS4.0

CVE-2024-6662 - CSRF in MegaBIP

Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms. A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If …

📅 Published: Jan. 10, 2025, 5:50 p.m. 🔄 Last Modified: July 13, 2025, 11:22 a.m.

6.4

CVSS4.0

CVE-2025-22600 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `configuracao_doacao.php` parameter `avul…

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the avulso parameter. This vulnerability is fi…

📅 Published: Jan. 10, 2025, 3:30 p.m. 🔄 Last Modified: April 9, 2025, 6:26 p.m.

6.4

CVSS4.0

CVE-2025-22599 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.

8.3

CVSS3.1

CVE-2025-22598 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'cadastrarSocio.php' parameter 'nome'

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scripts a…

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:34 a.m.

8.3

CVSS3.1

CVE-2025-22597 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'CobrancaController.php' parameter 'local_re…

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scrip…

📅 Published: Jan. 10, 2025, 3:28 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:33 a.m.

6.4

CVSS4.0

CVE-2025-22596 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint 'modulos_visiveis.php' parameter'msg_c'

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed …

📅 Published: Jan. 10, 2025, 3:27 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.

9.4

CVSS4.0

CVE-2025-22152 - Improper Path Validation Enables Path Traversal in Multiple Components in Atheos

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities can be exploited through various attack vecto…

📅 Published: Jan. 10, 2025, 3:23 p.m. 🔄 Last Modified: July 12, 2025, 3:26 p.m.

9.3

CVSS4.0

CVE-2024-56511 - DataEase has an unauthorized vulnerability

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter class, ”request.getReques…

📅 Published: Jan. 10, 2025, 3:19 p.m. 🔄 Last Modified: Feb. 20, 2025, 4:26 p.m.
Total resulsts: 343738
Page 6645 of 34,374
« previous page » next page
Filters