CVE-2025-55734 – FlaskBlog Unauthenticated Access to Sensitive Pages

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is “admin” only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when a user is trying to access the admin page, but that control is […]

CVE-2025-55306 – GenX FX Exposed API Keys and Authentication Tokens

The following table lists the changes that have been made to the CVE-2025-55306 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]

CVE-2025-55733 – DeepChat Custom URL Handler Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-55733 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]

CVE-2025-55303 – Astro Image Optimization Endpoint Protocol-Relative URL Injection

The following table lists the changes that have been made to the CVE-2025-55303 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]

CVE-2025-52338 – LogicData eCommerce Framework Authentication Bypass

The following table lists the changes that have been made to the CVE-2025-52338 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Aug. 19, 2025 Action Type […]

CVE-2025-33008 – IBM Sterling B2B Integrator Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-33008 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]

CVE-2025-50891 – Adform Site Tracking Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-50891 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Aug. 19, 2025 Action Type […]

CVE-2025-43745 – Liferay Portal CSRF Attack

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behalf of the authenticated user via the endpoint parameter.

CVE-2025-43737 – Liferay Portal Liferay DXP Reflected Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-43737 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]

CVE-2025-31988 – HCL Digital Experience Cross-Site Scripting (XSS) Vulnerability

The following table lists the changes that have been made to the CVE-2025-31988 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 19, 2025 Action […]