Latest CVE Feed
-
9.9
CRITICALCVE-2025-8795
A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login. The manipulation of the argument projectID leads to improper access controls. It is possible to initiate... Read more
Affected Products : litmus- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-8796
A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID ... Read more
Affected Products : litmus- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-8797
A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component LocalStorage Handler. The manipulation leads to permission issues. The attack may be initiated remotely. T... Read more
Affected Products : litmus- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-8812
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /api/settings of the component Admin Panel. The manipulation leads to cross site scripting. It is possible to initiate the... Read more
Affected Products : pybbs- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-8813
A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This vulnerability affects the function changeLanguage of the file src/main/java/co/yiiu/pybbs/controller/front/IndexController.java. The manipulation of the argument... Read more
Affected Products : pybbs- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-8814
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setCookie of the file src/main/java/co/yiiu/pybbs/util/CookieUtil.java. The manipulation leads to cross-site request forgery. The attack ma... Read more
Affected Products : pybbs- Published: Aug. 10, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-3733
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.... Read more
Affected Products : baguettebox.js- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-3734
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.... Read more
Affected Products : stage_file_proxy- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Denial of Service
-
5.9
MEDIUMCVE-2025-3735
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.... Read more
Affected Products : panelizer_\(obsolete\)- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
-
5.9
MEDIUMCVE-2025-3736
Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.... Read more
Affected Products : simple_gtm- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
-
5.9
MEDIUMCVE-2025-3737
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.... Read more
Affected Products : _store_locator_project- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
-
6.5
MEDIUMCVE-2024-33663
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.... Read more
Affected Products : python-jose- Published: Apr. 26, 2024
- Modified: Sep. 02, 2025
-
5.9
MEDIUMCVE-2025-3738
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.... Read more
Affected Products : google_optimize- Published: Apr. 16, 2025
- Modified: Sep. 02, 2025
-
7.3
HIGHCVE-2025-3903
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.... Read more
Affected Products : ueditor- Published: Apr. 23, 2025
- Modified: Sep. 02, 2025
-
7.3
HIGHCVE-2025-3904
Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.... Read more
Affected Products : sportsleague- Published: Apr. 23, 2025
- Modified: Sep. 02, 2025
-
4.3
MEDIUMCVE-2025-3907
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.... Read more
Affected Products : search_api_solr- Published: Apr. 23, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-52888
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.... Read more
- Published: Apr. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-52887
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.... Read more
- Published: Apr. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-33664
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.... Read more
Affected Products : python-jose- Published: Apr. 26, 2024
- Modified: Sep. 02, 2025
-
8.1
HIGHCVE-2025-31689
Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.... Read more
- Published: Mar. 31, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Request Forgery