Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.
CVSS Score
4.0
EPSS Score
0.0
Published
2025-09-30
This vulnerability affects Firefox < 143.0.3.
CVSS Score
8.6
EPSS Score
0.0
Published
2025-09-30
This vulnerability affects Firefox < 143.0.3.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-09-30
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in version 8.1.27.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-09-30
AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-09-30
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-09-30
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to planning counter details using unauthorised internal identifiers.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-09-30
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-09-30
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic employee details using unauthorised internal identifiers.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-09-30
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a  misuse of the general enquiry web service.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-09-30


Contact Us

Shodan ® - All rights reserved