7.5

CVSS3.1

CVE-2025-66909 -

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java loads images using OpenCV's imread() function without validating dimensions or pixel count before decomp…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

7.6

CVSS3.1

CVE-2025-67442 -

EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

4.9

CVSS3.1

CVE-2025-67846 -

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contain…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 2:01 a.m.

7.5

CVSS3.1

CVE-2025-66905 -

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

5.1

CVSS4.0

CVE-2025-14898 - CodeAstro Real Estate Management System Administrator Endpoint userbuilderdelete.php sql injection

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been…

πŸ“… Published: Dec. 18, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 11:32 p.m.

5.1

CVSS4.0

CVE-2025-14897 - CodeAstro Real Estate Management System Administrator Endpoint useragentdelete.php sql injection

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is pu…

πŸ“… Published: Dec. 18, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 11:32 p.m.

8.3

CVSS3.1

CVE-2025-64675 - Azure Cosmos DB Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: Dec. 18, 2025, 11:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 11:15 p.m.

9.1

CVSS3.1

CVE-2025-68398 - Weblate has git config file overwrite vulnerability that leads to remote code execution

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

πŸ“… Published: Dec. 18, 2025, 11 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

7.7

CVSS3.1

CVE-2025-68279 - Weblate has an arbitrary file read via symbolic links

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

πŸ“… Published: Dec. 18, 2025, 10:59 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 10:59 p.m.

4.3

CVSS3.1

CVE-2025-68422 - Kibana Improper Authorization

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of …

πŸ“… Published: Dec. 18, 2025, 10:32 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 10:32 p.m.
Total resulsts: 323543
Page 17 of 32,355
Β« previous page Β» next page
Filters