Show filters
349,137 Total Results
Displaying 11-20 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2025-25513
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
0
Attacker Value
Unknown
CVE-2024-57608
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
0
Attacker Value
Unknown
CVE-2025-27137
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templates. Templates are evaluated using the Pebble template engine. Pebble supports an `include` tag, which allows template authors to include the content of arbitrary files upon evaluation. Prior to version 4.12.6, users of Dependency-Track with the `SYSTEM_CONFIGURATION` permission can abuse the `include` tag by crafting notification templates that `include` sensitive local files, such as `/etc/passwd` or `/proc/1/environ`. By configuring such a template for a notification rule (aka "Alert"), and having it send notifications to a destination controlled by the actor, sensitive information may be leaked. The issue has been fixed in Dependency-Track 4.12.6. In fixed versions, the `include` tag can no longer be used. Usage of the tag will cause template eva…
0
Attacker Value
Unknown
CVE-2025-26533
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
An SQL injection risk was identified in the module list filter within course search.
0
Attacker Value
Unknown
CVE-2025-26532
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
0
Attacker Value
Unknown
CVE-2025-26531
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
0
Attacker Value
Unknown
CVE-2025-26530
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown
CVE-2025-26529
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Description information displayed in the site administration live log
required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2025-26528
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2025-26527
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
0