CVE-2025-36000 – IBM WebSphere Application Server Liberty Stored Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-36000 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-55169 – WeGIA Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-55169 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-55168 – WeGIA SQL Injection Vulnerability

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/saude/aplicar_medicamento.php endpoint, specifically in the id_fichamedica parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This […]

CVE-2025-53744 – FortiOS Security Fabric Privilege Escalation Vulnerability

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.

CVE-2025-52970 – Fortinet FortiWeb Unauthenticated Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-52970 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-49813 – Fortinet FortiADC OS Command Injection

The following table lists the changes that have been made to the CVE-2025-49813 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-32766 – Fortinet FortiWeb Stack-Based Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-32766 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-47857 – Fortinet FortiWeb OS Command Injection

The following table lists the changes that have been made to the CVE-2025-47857 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-43734 – Liferay Portal Liferay DXP Cross-Site Scripting (XSS) Vulnerability

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code in the “first display label” field in the configuration […]

CVE-2025-36124 – IBM WebSphere Application Server Liberty JMS Message Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-36124 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]