Show filters
349,160 Total Results
Displaying 31-40 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2025-26531

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
0
Attacker Value
Unknown

CVE-2025-26530

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown

CVE-2025-26529

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown

CVE-2025-26528

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown

CVE-2025-26527

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
0
Attacker Value
Unknown

CVE-2025-26526

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
0
Attacker Value
Unknown

CVE-2025-26525

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
0
Attacker Value
Unknown

CVE-2025-27364

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.
0
Attacker Value
Unknown

CVE-2025-27133

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.2.15 contains a patch for the issue.
0
Attacker Value
Unknown

CVE-2025-27112

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a "permission denied" error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.
0