Latest CVE Feed
-
8.5
HIGHCVE-2025-49580
XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts conta... Read more
Affected Products : xwiki- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-48920
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.... Read more
Affected Products : etracker- Published: Jun. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-48919
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48918
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-48917
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU Cookie Compliance (GDPR Compliance): from 0.0.0 bef... Read more
Affected Products : eu_cookie_compliance- Published: Jun. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48916
Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.... Read more
Affected Products : bookable_calendar- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-48915
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.... Read more
- Published: Jun. 13, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-48914
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.... Read more
- Published: Jun. 13, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-6030
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack conf... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cryptography
-
9.4
CRITICALCVE-2025-6029
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is ... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-36633
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-36631
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28389
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28388
OpenC3 COSMOS v6.0.0 was discovered to contain hardcoded credentials for the Service Account.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28386
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-28384
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-28382
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-28381
A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-28380
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46096
Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component... Read more
Affected Products : solon- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal