9.1

CVSS3.1

CVE-2025-1928 - Improper Authentication in Restajet's Online Food Delivery System

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 12:08 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

7.1

CVSS3.1

CVE-2025-1927 - CSRF in Restajet's Online Food Delivery System

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 12:01 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

5.4

CVSS3.1

CVE-2025-1885 - Open Redirect in Restajet's Online Food Delivery System

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing.This issue affects Online Food Delivery System: through 19122025.

πŸ“… Published: Dec. 19, 2025, 11:47 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 11:47 a.m.

8.7

CVSS4.0

CVE-2025-14847 - Zlib compressed protocol header length confusion may allow memory read

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, Mo…

πŸ“… Published: Dec. 19, 2025, 11 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 11 a.m.

5.4

CVSS3.1

CVE-2025-14455 - Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor…

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for …

πŸ“… Published: Dec. 19, 2025, 9:29 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:29 a.m.

4.3

CVSS3.1

CVE-2025-12361 - myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 -…

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This mak…

πŸ“… Published: Dec. 19, 2025, 9:29 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:29 a.m.

7.5

CVSS4.0

CVE-2025-66524 - Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without fil…

πŸ“… Published: Dec. 19, 2025, 9:24 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.4

CVSS3.1

CVE-2025-11747 - Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

πŸ“… Published: Dec. 19, 2025, 8:23 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 8:23 a.m.

6.1

CVSS3.1

CVE-2025-14151 - SlimStat Analytics <= 5.3.2 - Unauthenticated Stored Cross-Site Scripting

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' parameter in the slimtrack AJAX action in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. Th…

πŸ“… Published: Dec. 19, 2025, 8:23 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 8:23 a.m.

6.3

CVSS3.1

CVE-2025-66522 - Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Digital IDs Common Name Field

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, …

πŸ“… Published: Dec. 19, 2025, 7:34 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:34 a.m.
Total resulsts: 323546
Page 11 of 32,355
Β« previous page Β» next page
Filters