7.2

CVSS3.1

CVE-2025-66921 -

A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:52 p.m.

9.8

CVSS3.1

CVE-2025-67793 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administr…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:54 p.m.

7.2

CVSS3.1

CVE-2025-67172 -

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

7.1

CVSS3.1

CVE-2025-65203 -

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:45 p.m.

7.8

CVSS3.1

CVE-2025-67792 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrary commands on Windows computers.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2024-46060 -

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary comma…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:42 p.m.

6.1

CVSS3.1

CVE-2025-66924 -

A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:52 p.m.

9.9

CVSS3.1

CVE-2025-67781 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:55 p.m.

4.3

CVSS3.1

CVE-2025-43541 - webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 6:09 p.m.

3.1

CVSS3.1

CVE-2025-43531 - webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 7:21 p.m.
Total resulsts: 343825
Page 2026 of 34,383
Β« previous page Β» next page
Filters