Latest CVE Feed
-
9.4
CRITICALCVE-2025-54299
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-54298
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-50492
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : e-diary_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-50491
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : bank_locker_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-50489
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : student_result_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-50488
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : online_library_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
5.9
MEDIUMCVE-2025-43023
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cryptography
-
5.4
MEDIUMCVE-2025-7676
DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to lo... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-54538
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-54537
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-54536
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-54535
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2025-54534
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-54533
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-54532
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-54531
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54530
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-54529
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-54528
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-54527
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions... Read more
Affected Products : youtrack- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration