5.5

CVSS3.1

CVE-2025-68324 - scsi: imm: Fix use-after-free bug caused by unfinished delayed work

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

7.5

CVSS3.1

CVE-2025-65564 -

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:03 p.m.

7.5

CVSS3.1

CVE-2025-65565 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:06 p.m.

7.5

CVSS3.1

CVE-2025-65561 -

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9 p.m.

7.5

CVSS3.1

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:32 p.m.

5.4

CVSS3.1

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:36 p.m.

6.1

CVSS3.1

CVE-2025-63949 -

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:35 p.m.

6.1

CVSS3.1

CVE-2025-67163 -

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:58 p.m.

9.1

CVSS3.1

CVE-2025-63386 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains t…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Feb. 11, 2026, 3:16 p.m.

8.2

CVSS4.0

CVE-2025-14202 - Cross-Site Request Forgery (CSRF) Leading to Account Takeover via SVG File Upload

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the admin’s browser, retr…

πŸ“… Published: Dec. 17, 2025, 11:35 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:33 p.m.
Total resulsts: 342387
Page 1864 of 34,239
Β« previous page Β» next page
Filters