Show filters
349,105 Total Results
Displaying 101-110 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2025-25282

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts, add user account into other tenant). Unauthorized cross-tenant access: list user from other tenant (e.g., via GET /<tenant_id>/user/list), add user account to other tenant (POST /<tenant_id>/user). This issue has not yet been patched. Users are advised to reach out to the project maintainers to coordinate a fix.
0
Attacker Value
Unknown

CVE-2025-1555

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2025-25772

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
0
Attacker Value
Unknown

CVE-2025-25770

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
0
Attacker Value
Unknown

CVE-2025-25769

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.
0
Attacker Value
Unknown

CVE-2025-25768

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
0
Attacker Value
Unknown

CVE-2025-25767

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
0
Attacker Value
Unknown

CVE-2025-25605

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
0
Attacker Value
Unknown

CVE-2025-25604

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
0
Attacker Value
Unknown

CVE-2020-19248

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
0