6.4

CVSS3.1

CVE-2025-12885 - Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: Dec. 18, 2025, 1:51 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:07 p.m.

5.3

CVSS4.0

CVE-2025-14856 - y_project RuoYi getnames code injection

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicl…

πŸ“… Published: Dec. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:53 a.m.

4.8

CVSS4.0

CVE-2025-14841 - OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null point…

πŸ“… Published: Dec. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:53 a.m.

0.0

CVE-2025-68325 - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc w…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

9.1

CVSS3.1

CVE-2025-63388 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any ext…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 28, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-65568 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsi…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:06 p.m.

7.5

CVSS3.1

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:03 p.m.

7.5

CVSS3.1

CVE-2025-63757 - ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 8:04 p.m.

0.0

CVE-2025-68323 - usb: typec: ucsi: fix use-after-free caused by uec->work

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->work is scheduled in gaokun_ucsi_probe() but never properly canceled in gaokun_ucsi_remove(). This creates use-after-free scenarios where the ucsi and…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

9.8

CVSS3.1

CVE-2025-56157 -

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 6:16 p.m.
Total resulsts: 342297
Page 1853 of 34,230
Β« previous page Β» next page
Filters