CVE-2025-5964 Path traversal in M-Files API

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the...Read More ...

Continue Reading
CVE-2025-6158

creation_timestamp| type| source ---|---|--- 2025-06-15 19:16:06+00:00| seen|...Read More ...

Continue Reading
CVE-2024-25573

creation_timestamp| type| source ---|---|--- 2025-06-15 19:18:16+00:00| seen|...Read More ...

Continue Reading
CVE-2024-10099

creation_timestamp| type| source ---|---|--- 2025-06-15 18:42:19+00:00| seen|...Read More ...

Continue Reading
CVE-2025-5990

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form...Read M ...

Continue Reading
CVE-2025-5990 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Crafty Controller

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form...Read M ...

Continue Reading
CVE-2025-5990 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Crafty Controller

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form...Read M ...

Continue Reading
CVE-2025-36041

creation_timestamp| type| source ---|---|--- 2025-06-15 17:18:10+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: