3.1

CVSS3.1

CVE-2025-68940 - gitea: Gitea: Unauthorized branch deletion due to inadequate permission enforcement

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

πŸ“… Published: Dec. 26, 2025, 2:14 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:33 p.m.

8.2

CVSS3.1

CVE-2025-68939 - gitea: attachments can be renamed to forbidden file extensions via the attachment API

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

πŸ“… Published: Dec. 26, 2025, 2:03 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:35 p.m.

5.1

CVSS4.0

CVE-2025-15095 - postmanlabs httpbin core.py cross site scripting

A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. …

πŸ“… Published: Dec. 26, 2025, 2:02 a.m. πŸ”„ Last Modified: Dec. 29, 2025, 3:57 p.m.

5.3

CVSS4.0

CVE-2025-15094 - sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can …

πŸ“… Published: Dec. 26, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

4.3

CVSS3.1

CVE-2025-68938 - gitea: incorrect authorization for deletion of releases

Gitea before 1.25.2 mishandles authorization for deletion of releases.

πŸ“… Published: Dec. 26, 2025, 1:19 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:36 p.m.

5.3

CVSS4.0

CVE-2025-15093 - sunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting

A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected element is an unknown function of the file src/main/java/com/flycms/web/system/IndexAdminController.java of the component Admin Login. Performing a manipulation of the argument redir…

πŸ“… Published: Dec. 26, 2025, 1:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

8.7

CVSS4.0

CVE-2025-15092 - UTT 进取 512W ConfigExceptMSN strcpy buffer overflow

A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument remark leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 26, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 6:57 p.m.

6.5

CVSS3.1

CVE-2024-42718 -

A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 9:35 p.m.

7.5

CVSS3.1

CVE-2025-25341 -

A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 9:37 p.m.

6.1

CVSS3.1

CVE-2025-67349 -

A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 9:36 p.m.
Total resulsts: 343921
Page 1878 of 34,393
Β« previous page Β» next page
Filters