9.1

CVSS4.0

CVE-2025-66456 - Elysia vulnerable to prototype pollution with multiple standalone schema validation

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to…

πŸ“… Published: Dec. 9, 2025, 7:43 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:43 p.m.

7

CVSS3.1

CVE-2025-66214 - Ladybug has an XMLDecoder Deserialization Vulnerability (Java RCE)

Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the APIs /iaf/ladybug/api/report/{storage} and /iaf/ladybug/api/report/upload, which allow uploading gzip-compressed XML files with user-controllable conten…

πŸ“… Published: Dec. 9, 2025, 7:37 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:37 p.m.

6.9

CVSS4.0

CVE-2025-14337 - itsourcecode Student Management System new_grade.php sql injection

A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulation of the argument grade causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: Dec. 9, 2025, 7:32 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:32 p.m.

9.3

CVSS4.0

CVE-2025-64113 - Emby Server allows attackers to gain administrative server access without preconditions

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vul…

πŸ“… Published: Dec. 9, 2025, 7:21 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:21 p.m.

6.9

CVSS4.0

CVE-2025-14336 - itsourcecode Student Management System promote.php sql injection

A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.php. The manipulation of the argument sy results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and co…

πŸ“… Published: Dec. 9, 2025, 7:02 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-14335 - itsourcecode Student Management System new_school_year.php sql injection

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /new_school_year.php. The manipulation of the argument sy leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

πŸ“… Published: Dec. 9, 2025, 7:02 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:15 p.m.

0.0

CVE-2025-9613 - CVE-2025-9613

A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completi…

πŸ“… Published: Dec. 9, 2025, 6:52 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:52 p.m.

0.0

CVE-2025-9614 - CVE-2025-9614

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead t…

πŸ“… Published: Dec. 9, 2025, 6:48 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:48 p.m.

0.0

CVE-2025-9612 - CVE-2025-9612

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical…

πŸ“… Published: Dec. 9, 2025, 6:44 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:44 p.m.

6.9

CVSS4.0

CVE-2025-14334 - itsourcecode Student Management System new_adviser.php sql injection

A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipulation of the argument Name can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

πŸ“… Published: Dec. 9, 2025, 6:32 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:15 p.m.
Total resulsts: 321334
Page 1 of 32,134
Β» next page
Filters