5.1

CVSS4.0

CVE-2019-25228 - Kentico Xperience <= 12.0.47 Virtual Context Information Disclosure

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/im…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

4.1

CVSS3.1

CVE-2025-64400 - Insufficient permission checks when pre-enrolling users Summary

Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment …

πŸ“… Published: Dec. 18, 2025, 7:32 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:32 p.m.

7.1

CVSS3.1

CVE-2025-67745 - Myhoard logs backup encryption key in plain text

MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, including the encryption key. Version 1.3.0 fixes the issue. As a workaround, direct logs into /dev/null.

πŸ“… Published: Dec. 18, 2025, 6:37 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-14885 - SourceCodester Client Database Management System Leads Generation user_leads.php unrestricted upload

A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publish…

πŸ“… Published: Dec. 18, 2025, 6:32 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:32 p.m.

5.3

CVSS3.1

CVE-2025-59949 - FreshRSS has Logout CSRF that Leads to DoS via <track src>

FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.

πŸ“… Published: Dec. 18, 2025, 6:31 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:31 p.m.

6.8

CVSS4.0

CVE-2025-14739 - Uninitialized Pointer Vulnerability in TP-Link WR940N and WR941ND

Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allowsΒ local unauthenticated attackers the ability to execute DoS attack and potentially arbitrary code execution under the context of the β€˜root’ user.This issue affects WR940N and WR941ND: ≀ WR940N v5 3.20.1 Build 20031…

πŸ“… Published: Dec. 18, 2025, 6:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:02 p.m.

5.7

CVSS4.0

CVE-2025-14738 - Configuration Disclosure Vulnerability in TP-Link WA850RE

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≀ WA850RE V2_160527, ≀ WA850RE V3_160922.

πŸ“… Published: Dec. 18, 2025, 6:01 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:01 p.m.

7.1

CVSS4.0

CVE-2025-14737 - Command Injection Vulnerability in TP-Link WA850RE

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≀ WA850RE V2_160527, ≀ WA850RE V3_160922.

πŸ“… Published: Dec. 18, 2025, 6 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6 p.m.

8.6

CVSS4.0

CVE-2025-14884 - D-Link DIR-605 Firmware Update Service command injection

A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnera…

πŸ“… Published: Dec. 18, 2025, 5:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:02 p.m.

9.3

CVSS4.0

CVE-2025-14879 - Tenda WH450 HTTP Request onSSIDChange stack-based overflow

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: Dec. 18, 2025, 5:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:02 p.m.
Total resulsts: 323423
Page 14 of 32,343
Β« previous page Β» next page
Filters