6

CVSS3.1

CVE-2025-66910 -

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon successful login, ra…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

0.0

CVE-2025-63665 -

An issue in GT Edge AI Platform Versions before v2.0.10-dev allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-66905 -

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

4.9

CVSS3.1

CVE-2025-67846 -

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contain…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2:01 a.m.

7.6

CVSS3.1

CVE-2025-67442 -

EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.4

CVSS3.1

CVE-2025-67845 -

A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.1

CVSS3.1

CVE-2025-66906 -

Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

5

CVSS3.1

CVE-2025-67844 -

The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the specific GitHub App …

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 1:59 a.m.

4.3

CVSS3.1

CVE-2025-14969 - io.quarkus/quarkus-hibernate-reactive-panache: Hibernate Reactive: Denial of Service due to connect…

No description is available for this CVE.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, midnight

8.3

CVSS3.1

CVE-2025-67843 -

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 1:58 a.m.
Total resulsts: 323543
Page 16 of 32,355
Β« previous page Β» next page
Filters