5.4

CVSS3.1

CVE-2025-64177 - ThinkDashboard: Stored XSS in Dashboard via Malicious Bookmark

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, there is a stored Cross-Site Scripting (XSS) vulnerability in the dashboard, which can exploited when a user clicks on a malicious bookmark, made vulnerable by the lack of scheme fi…

📅 Published: Nov. 6, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

5.3

CVSS3.1

CVE-2025-64176 - ThinkDashboard: Arbitrary File Upload vulnerability in the Backup Import Feature

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file they wish to the /data directory of the web application via the backup import feature. When importing a backup, an attacker can first choose a .zip f…

📅 Published: Nov. 6, 2025, 9:12 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

5.3

CVSS3.1

CVE-2025-64327 - ThinkDashboard: Blind Server-Side Request Forgery (SSRF) vulnerability in /api/ping Endpoint

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in its `/api/ping?url= endpoint`. This allows an attacker to make arbitrary requests to internal or external hosts. Thi…

📅 Published: Nov. 6, 2025, 9:07 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

2.6

CVSS3.1

CVE-2025-64326 - Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit log

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in…

📅 Published: Nov. 6, 2025, 8:55 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

4.6

CVSS4.0

CVE-2025-64174 - OpenMage is vulnerable to XSS in Admin Notifications

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scrip…

📅 Published: Nov. 6, 2025, 8:45 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

5.4

CVSS3.1

CVE-2025-33110 - IBM OpenPages Vulnerable to HTML Injection

IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

📅 Published: Nov. 6, 2025, 8:43 p.m. 🔄 Last Modified: Nov. 6, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2025-64173 - Apollo Router Core: Access Control Bypass on Polymorphic Types

Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access contr…

📅 Published: Nov. 6, 2025, 8:42 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

8.8

CVSS3.0

CVE-2025-12486 - Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability

Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific fl…

📅 Published: Nov. 6, 2025, 8:12 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

9.8

CVSS3.0

CVE-2025-12487 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…

📅 Published: Nov. 6, 2025, 8:12 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

9.8

CVSS3.0

CVE-2025-12488 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…

📅 Published: Nov. 6, 2025, 8:11 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.
Total resulsts: 317360
Page 12 of 31,736
« previous page » next page
Filters