9.3

CVSS4.0

CVE-2025-14733 - WatchGuard Firebox iked Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability a…

πŸ“… Published: Dec. 19, 2025, 12:01 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 11:20 p.m.

6.4

CVSS3.1

CVE-2025-67845 -

A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2 a.m.

0.0

CVE-2025-66905 -

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 3:17 p.m.

4.9

CVSS3.1

CVE-2025-67846 -

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contain…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2:01 a.m.

0.0

CVE-2025-66909 -

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java loads images using OpenCV's imread() function without validating dimensions or pixel count before decomp…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2:21 p.m.

6.4

CVSS3.1

CVE-2025-67842 -

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 1:45 a.m.

0.0

CVE-2025-66910 -

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon successful login, ra…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2:50 p.m.

0.0

CVE-2025-63665 -

An issue in GT Edge AI Platform Versions before v2.0.10-dev allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 8:33 p.m.

8.3

CVSS3.1

CVE-2025-67843 -

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 1:58 a.m.

0.0

CVE-2025-66906 -

Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 3:08 p.m.
Total resulsts: 323513
Page 13 of 32,352
Β« previous page Β» next page
Filters