7.2

CVSS3.0

CVE-2025-13700 - DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementati…

📅 Published: Dec. 23, 2025, 9:42 p.m. 🔄 Last Modified: Dec. 29, 2025, 3:58 p.m.

10

CVSS3.1

CVE-2025-66209 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrar…

📅 Published: Dec. 23, 2025, 9:42 p.m. 🔄 Last Modified: March 17, 2026, 5:16 p.m.

7.8

CVSS3.1

CVE-2025-12840 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:46 p.m.

7.8

CVSS3.1

CVE-2025-12839 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:45 p.m.

7.8

CVSS3.1

CVE-2025-12495 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:45 p.m.

7.3

CVSS3.0

CVE-2025-12838 - MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability

MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Dec. 29, 2025, 3:58 p.m.

4.5

CVSS3.0

CVE-2025-13698 - Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability

Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific fl…

📅 Published: Dec. 23, 2025, 9:40 p.m. 🔄 Last Modified: Dec. 29, 2025, 3:58 p.m.

7.8

CVSS3.0

CVE-2025-13715 - Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerabi…

Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent FaceDetection-DSFD. User interaction is required to exploit this vulnerability in that t…

📅 Published: Dec. 23, 2025, 9:38 p.m. 🔄 Last Modified: Dec. 29, 2025, 3:58 p.m.

7.8

CVSS3.0

CVE-2025-13709 - Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerabil…

Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must…

📅 Published: Dec. 23, 2025, 9:34 p.m. 🔄 Last Modified: Jan. 12, 2026, 5:37 p.m.

7.8

CVSS3.0

CVE-2025-13711 - Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability

Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must visit a malic…

📅 Published: Dec. 23, 2025, 9:34 p.m. 🔄 Last Modified: Jan. 12, 2026, 5:36 p.m.
Total resulsts: 344064
Page 1949 of 34,407
« previous page » next page
Filters