6.9

CVSS4.0

CVE-2025-14704 - Shiguangwu sgwbox N3 API eshell path traversal

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor waโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 2:28 a.m.

6.9

CVSS4.0

CVE-2025-14703 - Shiguangwu sgwbox N3 POST Message fsnotify improper authentication

A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POST Message Handler. The manipulation of the argument token leads to improper authentication. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 2:27 a.m.

0.0

CVE-2025-67907 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67906. Reason: This candidate is a reservation duplicate of CVE-2025-67906. Notes: All CVE users should reference CVE-2025-67906 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidentaโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 3:33 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 3:48 a.m.

4.8

CVSS4.0

CVE-2025-14702 - Smartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversal

A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component be.smartschool.mobile.SplashActivity. Executing manipulation can lead to path traversal. The attack requires local access. The exploit has been published and may be used. The vendoโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 7 p.m.

5.4

CVSS3.1

CVE-2025-67906 -

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

๐Ÿ“… Published: Dec. 15, 2025, 3:25 a.m. ๐Ÿ”„ Last Modified: Dec. 21, 2025, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-13740 - Lightweight Accordion <= 1.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 3:20 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

4.8

CVSS4.0

CVE-2025-14699 - Municorn FAX App biz.faxapp.app path traversal

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Thโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 7:35 p.m.

4.8

CVSS4.0

CVE-2025-14698 - atlaszz AI Photo Team Galleryit App gallery.photogallery.pictures.vault.album path traversal

A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been made available toโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 7:35 p.m.

6.3

CVSS4.0

CVE-2025-14697 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System ExportFiles file access

A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or directories accessible. The attack may be launched remotely.โ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 7:23 p.m.

6.9

CVSS4.0

CVE-2025-14696 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System UpdatePasswordBatch passworโ€ฆ

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiโ€ฆ

๐Ÿ“… Published: Dec. 15, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 7:32 p.m.
Total resulsts: 343040
Page 1997 of 34,304
ยซ previous page ยป next page
Filters