0.0

CVE-2025-65176 -

An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt to access the netwo…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 6:48 p.m.

0.0

CVE-2025-66438 -

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(t…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2025-66436 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom …

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2023-36337 -

A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 6:33 p.m.

0.0

CVE-2025-66439 -

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the fr…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2025-66440 -

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the to…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

8.8

CVSS3.1

CVE-2024-44598 -

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

0.0

CVE-2025-66437 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a str…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2025-66434 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a cust…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

6.5

CVSS3.1

CVE-2025-55901 -

TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.
Total resulsts: 322431
Page 15 of 32,244
Β« previous page Β» next page
Filters