Latest CVE Feed
-
5.4
MEDIUMCVE-2025-46923
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46922
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
4.6
MEDIUMCVE-2025-46920
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46919
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-3004
A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The ... Read more
Affected Products : forestblog- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-31116
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to... Read more
Affected Products : mobile_security_framework- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
6.3
MEDIUMCVE-2025-29405
An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : emlog- Published: Mar. 19, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-51322
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-4256
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The ex... Read more
Affected Products : seacms- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-45240
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.... Read more
- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-45238
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.... Read more
Affected Products : foxcms- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-45239
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.... Read more
- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-4327
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the pub... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-4329
A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be la... Read more
Affected Products : 74cms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2024-8012
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : workspace_control- Published: Sep. 10, 2024
- Modified: Jun. 12, 2025
-
8.8
HIGHCVE-2024-44107
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.... Read more
Affected Products : workspace_control- Published: Sep. 10, 2024
- Modified: Jun. 12, 2025
-
8.8
HIGHCVE-2024-44106
Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : workspace_control- Published: Sep. 10, 2024
- Modified: Jun. 12, 2025
-
8.2
HIGHCVE-2024-44105
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.... Read more
Affected Products : workspace_control- Published: Sep. 10, 2024
- Modified: Jun. 12, 2025
-
8.8
HIGHCVE-2024-44104
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : workspace_control- Published: Sep. 10, 2024
- Modified: Jun. 12, 2025