9.3

CVSS4.0

CVE-2023-53894 - phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

πŸ“… Published: Dec. 16, 2025, 5:03 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

8.5

CVSS4.0

CVE-2025-68130 - tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router …

πŸ“… Published: Dec. 16, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

8.9

CVSS3.1

CVE-2025-68116 - FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) o…

πŸ“… Published: Dec. 16, 2025, 4:43 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 4:48 p.m.

6.5

CVSS3.1

CVE-2025-59935 - GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.

πŸ“… Published: Dec. 16, 2025, 4:34 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 2:59 p.m.

10

CVSS3.1

CVE-2025-37164 -

A remote code execution issue exists in HPE OneView.

πŸ“… Published: Dec. 16, 2025, 4:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.1

CVSS4.0

CVE-2025-10450 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Prof…

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.2.0 before 7.3.1.

πŸ“… Published: Dec. 16, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 2:16 a.m.

5.4

CVSS3.1

CVE-2025-68269 -

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:07 p.m.

5.4

CVSS3.1

CVE-2025-68268 -

In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:11 p.m.

6.5

CVSS3.1

CVE-2025-68267 -

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

5.4

CVSS3.1

CVE-2025-68166 -

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.
Total resulsts: 343761
Page 2025 of 34,377
Β« previous page Β» next page
Filters