4.3

CVSS3.1

CVE-2023-50738 - A firmware downgrade prevention vulnerability has been identified in newer Lexmark devices.

A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.

📅 Published: Jan. 17, 2025, 9:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0540 - itsourcecode Tailoring Management System expadd.php sql injection

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be initiated remotely. The exploit has been disc…

📅 Published: Jan. 17, 2025, 9 p.m. 🔄 Last Modified: Feb. 7, 2025, 2:58 p.m.

1.8

CVSS4.0

CVE-2025-23206 - IAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdk

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. …

📅 Published: Jan. 17, 2025, 8:34 p.m. 🔄 Last Modified: Jan. 23, 2026, 3:16 p.m.

5.3

CVSS4.0

CVE-2025-0538 - code-projects Tourism Management System manage-pages.php cross site scripting

A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotel…

📅 Published: Jan. 17, 2025, 8:31 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-23205 - `frame-ancestors: self` grants all users access to formgrader in nbgrader

nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomai…

📅 Published: Jan. 17, 2025, 8:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-23202 - Improper Input Validation in Bible Module for ROBLOX

Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse` and `FetchPassage` functions in the Bible Module are susceptible to injection attacks due to the absence of input validation. This vulnerability could allow an attacker to manip…

📅 Published: Jan. 17, 2025, 8:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS3.1

CVE-2025-23039 - Cross Site Scripting on URL decode Tooltip in Caido

Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due to improper sanitization in the URL decoding tooltip of HTTP request and response editors. This issue could allow an attacker to execute arbitrary scripts, potentially leading to…

📅 Published: Jan. 17, 2025, 8:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-21606 - Local Privilege Escalation via Exposed XPC Method Due to Client Verification Failure in stats

stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation due to the insecure implementation of its XPC service. The application registers a Mach service under the name `eu.exelban.Stats.SMC.Helper`. The associated binary, eu.exelban.St…

📅 Published: Jan. 17, 2025, 8:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS4.0

CVE-2024-13026 - Inadequate Encryption Strength Vulnerability in Roche Algo Edge

A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft v…

📅 Published: Jan. 17, 2025, 8:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-0537 - code-projects Car Rental Management System manage-pages.php cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cross site scripting. The attack may be initiat…

📅 Published: Jan. 17, 2025, 8 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.
Total resulsts: 346671
Page 6806 of 34,668
« previous page » next page
Filters