8.7

CVSS4.0

CVE-2025-15356 - Tenda AC20 PowerSaveSet sscanf buffer overflow

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer overflow. The attack can be initiated remotely. The exploit h…

πŸ“… Published: Dec. 30, 2025, 8:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:19 a.m.

1.3

CVSS4.0

CVE-2025-14986 - ExecuteMultiOperation Namespace Policy Bypass

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized…

πŸ“… Published: Dec. 30, 2025, 8:17 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

5.3

CVSS4.0

CVE-2025-14987 - Cross Namespace Commands Authorization Bypass

When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a different namespace than the namespace authorized a…

πŸ“… Published: Dec. 30, 2025, 8:16 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

6.9

CVSS4.0

CVE-2025-15354 - itsourcecode Society Management System add_admin.php sql injection

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published …

πŸ“… Published: Dec. 30, 2025, 8:02 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

5.5

CVSS4.0

CVE-2025-69261 - WasmEdge integer wrap in MemoryInstance::getSpan()'s memory size check

WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.

πŸ“… Published: Dec. 30, 2025, 7:43 p.m. πŸ”„ Last Modified: March 9, 2026, 1:55 p.m.

6.9

CVSS4.0

CVE-2025-15353 - itsourcecode Society Management System edit_admin_query.php edit_admin_query sql injection

A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of the file /admin/edit_admin_query.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is no…

πŸ“… Published: Dec. 30, 2025, 7:32 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

1.2

CVSS4.0

CVE-2025-69210 - FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. Authenticated users can upload crafted XML files containing executable JavaScript. These fi…

πŸ“… Published: Dec. 30, 2025, 7:23 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 3:23 p.m.

6.7

CVSS3.1

CVE-2025-69257 - theshit vulnerable to unsafe loading of user-owned Python rules when running as root.

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.config/theshit/`) without validating ownership or permissions w…

πŸ“… Published: Dec. 30, 2025, 7:15 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 8:42 p.m.

7.5

CVSS3.1

CVE-2025-69256 - serverless MCP Server vulnerable to command injection in list-projects tool

The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and prior to version 4.29.3, a command injection vulnerability exists in the Serverless Framework's built-in MCP server package (@serverless/mcp). This vul…

πŸ“… Published: Dec. 30, 2025, 7:05 p.m. πŸ”„ Last Modified: March 23, 2026, 2:42 p.m.

6.9

CVSS4.0

CVE-2025-15264 - FeehiCMS TimThumb timthumb.php server-side request forgery

A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThumb. Executing manipulation of the argument src can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publ…

πŸ“… Published: Dec. 30, 2025, 7:02 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 5:44 p.m.
Total resulsts: 343919
Page 1816 of 34,392
Β« previous page Β» next page
Filters