Vulnerability Database

300,926

Total vulnerabilities in the database

CVE-2025-5254

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.

  • Published: Jul 25, 2025
  • Updated: Jul 26, 2025
  • CVE: CVE-2025-5254
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N