7.5

CVSS3.1

CVE-2024-29371 - jose4j: From CVEorg collector

In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during โ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 23, 2026, 8:15 p.m.

5.3

CVSS3.1

CVE-2025-67168 -

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

7.2

CVSS3.1

CVE-2025-66923 -

A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:52 p.m.

9.6

CVSS3.1

CVE-2025-67787 -

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:55 p.m.

5.3

CVSS3.1

CVE-2025-67789 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:42 p.m.

8.8

CVSS3.1

CVE-2025-14766 - chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Dec. 16, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

8.8

CVSS3.1

CVE-2025-14765 - chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruptโ€ฆ

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Dec. 16, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

8.6

CVSS4.0

CVE-2025-34288 - Nagios XI Privilege Escalation via Writable PHP Include Executed with Sudo

Nagios XI versions prior to 2026R1.1 areย vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A userโ€‘accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a loweโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 12:03 p.m.

8.7

CVSS4.0

CVE-2025-68274 - SIPGO library has response DoS vulnerability via nil pointer dereference

SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference vulnerability is in the SIPGO library's `NewResponseFromRequest` function that affects all normal SIP operations. The vulnerability allows remote aโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 7:52 p.m.

6.5

CVSS3.1

CVE-2025-64520 - GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.

๐Ÿ“… Published: Dec. 16, 2025, 9:59 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 4:20 p.m.
Total resulsts: 343923
Page 2037 of 34,393
ยซ previous page ยป next page
Filters