Vulnerabilities (CVE)

Total 306886 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-11623 1 Goauthentik 1 Authentik 2025-08-21 N/A 4.8 MEDIUM
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
CVE-2025-29928 1 Goauthentik 1 Authentik 2025-08-21 N/A 8.0 HIGH
authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have access to authentik. authentik 2025.2.3 and 2024.12.4 fix this issue. Switching to the cache-based session storage until the authentik instance can be upgraded is recommended. This will however also delete all existing sessions and users will have to re-authenticate.
CVE-2025-9154 1 Mayurik 1 Online Tour \& Travel Management System 2025-08-21 7.5 HIGH 7.3 HIGH
A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2025-55737 1 Dogukanurker 1 Flaskblog 2025-08-21 N/A 6.5 MEDIUM
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code that causes the problem is in routes/post.py.
CVE-2025-9155 1 Mayurik 1 Online Tour \& Travel Management System 2025-08-21 7.5 HIGH 7.3 HIGH
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-9156 1 Angeljudesuarez 1 Sports Management System 2025-08-21 7.5 HIGH 7.3 HIGH
A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVE-2025-54143 1 Mozilla 1 Firefox 2025-08-21 N/A 9.8 CRITICAL
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.
CVE-2025-54144 1 Mozilla 1 Firefox 2025-08-21 N/A 5.4 MEDIUM
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.
CVE-2025-54145 1 Mozilla 1 Firefox 2025-08-21 N/A 9.1 CRITICAL
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141.
CVE-2025-52553 1 Goauthentik 1 Authentik 2025-08-21 N/A 9.6 CRITICAL
authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however this check is missing in versions prior to 2025.6.3 and 2025.4.3. When, for example, using RAC during a screenshare, a malicious user could access the same session by copying the URL from the shown browser. authentik 2025.4.3 and 2025.6.3 fix this issue. As a workaround, it is recommended to decrease the duration a token is valid for (in the RAC Provider settings, set Connection expiry to `minutes=5` for example). The maintainers of authentik also recommend enabling the option Delete authorization on disconnect.
CVE-2025-55028 1 Mozilla 1 Firefox 2025-08-21 N/A 6.5 MEDIUM
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55029 1 Mozilla 1 Firefox 2025-08-21 N/A 7.5 HIGH
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55030 1 Mozilla 1 Firefox 2025-08-21 N/A 6.1 MEDIUM
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55031 1 Mozilla 2 Firefox, Firefox Focus 2025-08-21 N/A 9.8 CRITICAL
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
CVE-2025-55032 1 Mozilla 1 Firefox Focus 2025-08-21 N/A 6.1 MEDIUM
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks This vulnerability affects Focus for iOS < 142.
CVE-2025-55033 1 Mozilla 1 Firefox Focus 2025-08-21 N/A 6.1 MEDIUM
Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
CVE-2025-8364 2 Google, Mozilla 2 Android, Firefox 2025-08-21 N/A 4.3 MEDIUM
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.
CVE-2025-9167 1 Solidinvoice 1 Solidinvoice 2025-08-21 4.0 MEDIUM 3.5 LOW
A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-9168 1 Solidinvoice 1 Solidinvoice 2025-08-21 4.0 MEDIUM 3.5 LOW
A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of the argument Client Name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-9179 1 Mozilla 2 Firefox, Thunderbird 2025-08-21 N/A 9.8 CRITICAL
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.