6.1

CVSS3.1

CVE-2025-67703 - Stored XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

πŸ“… Published: Dec. 31, 2025, 10:13 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 7:15 p.m.

6.3

CVSS4.0

CVE-2025-15398 - Uasoft badaso Token BadasoAuthController.php forgetPassword password recovery

A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The attack can be executed remotely. This attack i…

πŸ“… Published: Dec. 31, 2025, 10:02 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:36 p.m.

9.1

CVSS3.1

CVE-2025-69288 - Titra has Remote Code Execution in Admin Functionality

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.9…

πŸ“… Published: Dec. 31, 2025, 9:55 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 3:25 p.m.

8.9

CVSS4.0

CVE-2025-69286 - RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens a…

πŸ“… Published: Dec. 31, 2025, 9:52 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 4:47 p.m.

7.1

CVSS4.0

CVE-2023-7332 - PocketMine-MP < 4.18.1 Improper Validation of Dropped Item Count Allows Remote Server Crash

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting i…

πŸ“… Published: Dec. 31, 2025, 9:37 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 4:45 p.m.

6.9

CVSS4.0

CVE-2025-34469 - Cowrie < 2.9.0 Unrestricted wget/curl Emulation Enables SSRF-Based DDoS Amplification

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound HTTP requests to attacker-supplied destinations. Because no ou…

πŸ“… Published: Dec. 31, 2025, 9:36 p.m. πŸ”„ Last Modified: March 5, 2026, 12:04 p.m.

8.6

CVSS4.0

CVE-2025-68700 - RAGFlow Remote Code Execution Vulnerability

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas CodeExec component, completely bypassing sandbox is…

πŸ“… Published: Dec. 31, 2025, 9:17 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 6:02 p.m.

5.1

CVSS4.0

CVE-2023-7331 - PKrystian Full-Stack-Bank User sql injection

A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerability affects unknown code of the component User Handler. Performing manipulation results in sql injection. It is possible to initiate the attack remotely. This product is using a …

πŸ“… Published: Dec. 31, 2025, 9:02 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 4:45 p.m.

8.7

CVSS4.0

CVE-2015-10145 - Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shel…

πŸ“… Published: Dec. 31, 2025, 8:48 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

0.0

CVE-2025-53235 - WordPress Easy Social plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3.

πŸ“… Published: Dec. 31, 2025, 8:11 p.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.
Total resulsts: 343968
Page 1796 of 34,397
Β« previous page Β» next page
Filters