Show filters
349,160 Total Results
Displaying 31-40 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2025-26531
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
0
Attacker Value
Unknown
CVE-2025-26530
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown
CVE-2025-26529
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Description information displayed in the site administration live log
required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2025-26528
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2025-26527
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
0
Attacker Value
Unknown
CVE-2025-26526
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Separate Groups mode restrictions were not factored into permission
checks before allowing viewing or deletion of responses in Feedback
activities.
0
Attacker Value
Unknown
CVE-2025-26525
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient sanitizing in the TeX notation filter resulted in an
arbitrary file read risk on sites where pdfTeX is available (such as
those with TeX Live installed).
0
Attacker Value
Unknown
CVE-2025-27364
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.
0
Attacker Value
Unknown
CVE-2025-27133
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.2.15 contains a patch for the issue.
0
Attacker Value
Unknown
CVE-2025-27112
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a "permission denied" error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.
0