8.2

CVSS3.1

CVE-2025-65742 -

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

4.7

CVSS3.1

CVE-2025-67809 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:15 p.m.

5.3

CVSS3.1

CVE-2023-36338 -

Inventory Management System 1 was discovered to contain a SQL injection vulnerability.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:10 p.m.

0.0

CVE-2025-66843 -

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later exe…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2025-65780 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privileg…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

0.0

CVE-2025-65778 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token thef…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

8.8

CVSS3.1

CVE-2025-60786 -

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:33 p.m.

5.3

CVSS3.1

CVE-2023-38913 -

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:09 p.m.

2.5

CVSS3.1

CVE-2025-55703 -

An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outdated API endpoint that applied arrays without proper input validation. This can allow attackers to manipulate SQL queries. This has been addressed in Power IQ version 9.2.1, where…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 8:15 p.m.

0.0

CVE-2025-55895 -

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 9:15 p.m.
Total resulsts: 322431
Page 17 of 32,244
Β« previous page Β» next page
Filters