6.3

CVSS4.0

CVE-2025-69226 - AIOHTTP allows for a brute-force leak of internal static ๏ฌlepath components

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.statiโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

6.3

CVSS4.0

CVE-2025-69224 - AIOHTTP's Unicode processing of header values could cause parsing discrepancies

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) โ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 10:35 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 7:12 p.m.

7

CVSS4.0

CVE-2025-68456 - Unauthenticated Craft CMS users can trigger a database backup

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update tโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 10:03 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:19 p.m.

7.5

CVSS3.1

CVE-2025-69223 - AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. โ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 10 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 7:11 p.m.

8.6

CVSS4.0

CVE-2025-68455 - Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behaviโ€ฆ

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for thโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:59 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:21 p.m.

5.2

CVSS4.0

CVE-2025-68454 - Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChangโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:56 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:23 p.m.

7.5

CVSS3.1

CVE-2025-68953 - Certain Frappe requests are vulnerable to Path Traversal

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This issue is fixed in veโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:53 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 1:55 p.m.

5

CVSS4.0

CVE-2025-68437 - Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file` input, specifically iโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:52 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:28 p.m.

4.9

CVSS4.0

CVE-2025-68436 - Craft CMS vulnerable to potential information disclosure via unchecked asset relocation

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the pโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:46 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:29 p.m.

9.2

CVSS4.0

CVE-2025-68428 - jsPDF has Local File Inclusion/Path Traversal vulnerability

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file cโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:43 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 6:34 p.m.
Total resulsts: 346442
Page 2009 of 34,645
ยซ previous page ยป next page
Filters