5.3

CVSS3.1

CVE-2025-13820 - Comments โ€“ wpDiscuz < 7.6.40 - Unauthenticated Account Takeover

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

๐Ÿ“… Published: Jan. 1, 2026, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 5, 2026, 8:16 p.m.

5.3

CVSS3.1

CVE-2025-69413 - Gitea: Gitea: Information disclosure via differing authentication responses

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

๐Ÿ“… Published: Jan. 1, 2026, 4:39 a.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 7:27 p.m.

8.1

CVSS3.1

CVE-2025-12805 - Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user iโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 11:59 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 3:55 a.m.

3.4

CVSS3.1

CVE-2025-69412 -

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.

๐Ÿ“… Published: Dec. 31, 2025, 11:20 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 4:45 p.m.

6.1

CVSS3.1

CVE-2025-67711 - Reflected XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโ€™s browser.

๐Ÿ“… Published: Dec. 31, 2025, 10:18 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 7:03 p.m.

6.1

CVSS3.1

CVE-2025-67710 - Stored XSS vulnerability in ArcGIS Server

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโ€™s browser.

๐Ÿ“… Published: Dec. 31, 2025, 10:18 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 7:04 p.m.

6.1

CVSS3.1

CVE-2025-67709 - There is a cross site scripting issue in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโ€™s browser.

๐Ÿ“… Published: Dec. 31, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 7:04 p.m.

6.1

CVSS3.1

CVE-2025-67708 - Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโ€™s browser.

๐Ÿ“… Published: Dec. 31, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 7:04 p.m.

5.6

CVSS3.1

CVE-2025-67707 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the serverโ€™s designated upload directories. However, the serverโ€™s architecture enforces controls that restrict uploaded โ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 10:16 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 2:48 p.m.

5.6

CVSS3.1

CVE-2025-67706 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the serverโ€™s designated upload directories. However, the serverโ€™s architecture enforces controls that restrict uploaded โ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 10:15 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 9:29 p.m.
Total resulsts: 343970
Page 1795 of 34,397
ยซ previous page ยป next page
Filters