Latest CVE Feed
-
5.3
MEDIUMCVE-2025-53498
Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-53480
The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by appending ?uselang=x-xss to the URL, causi... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29267
SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter in the GET request.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-48920
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.... Read more
Affected Products : etracker- Published: Jun. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-48917
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU Cookie Compliance (GDPR Compliance): from 0.0.0 bef... Read more
Affected Products : eu_cookie_compliance- Published: Jun. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-35146
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functional... Read more
Affected Products : maximo_application_suite- Published: Nov. 06, 2024
- Modified: Jul. 08, 2025
-
5.3
MEDIUMCVE-2024-35144
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.... Read more
Affected Products : maximo_application_suite- Published: Jan. 25, 2025
- Modified: Jul. 08, 2025
-
6.1
MEDIUMCVE-2024-35145
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi... Read more
Affected Products : maximo_application_suite- Published: Jan. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-35148
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-... Read more
Affected Products : maximo_application_suite- Published: Jan. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-35150
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.... Read more
Affected Products : maximo_application_suite- Published: Jan. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-53499
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-53496
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects Mediawiki - MediaSearch Extension: from 1.42.X before ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-53495
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-31022
Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU PayU India allows Authentication Abuse.This issue affects PayU India: from n/a before 3.8.8.... Read more
Affected Products : payu_india_payment_gateway- Published: Jun. 09, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
8.0
HIGHCVE-2025-1500
IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.... Read more
Affected Products : maximo_application_suite- Published: Apr. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-0158
IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.... Read more
- Published: Feb. 06, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
3.3
LOWCVE-2025-0759
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Race Condition
-
9.3
HIGHCVE-2020-1171
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2... Read more
- Published: May. 21, 2020
- Modified: Jul. 08, 2025
-
9.3
HIGHCVE-2020-1192
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-... Read more
- Published: May. 21, 2020
- Modified: Jul. 08, 2025
-
5.9
MEDIUMCVE-2024-38314
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.... Read more
Affected Products : maximo_application_suite- Published: Oct. 24, 2024
- Modified: Jul. 08, 2025