5.4

CVSS3.1

CVE-2025-68166 -

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

5.4

CVSS3.1

CVE-2025-68165 -

In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

2.7

CVSS3.1

CVE-2025-68164 -

In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:22 p.m.

3.5

CVSS3.1

CVE-2025-68163 -

In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:23 p.m.

2.7

CVSS3.1

CVE-2025-68162 -

In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:24 p.m.

8.1

CVSS4.0

CVE-2025-14432 - Poly Video - Sensitive Data Might Be Written to Log File

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration c…

πŸ“… Published: Dec. 16, 2025, 3:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:54 p.m.

5

CVSS3.1

CVE-2025-62329 - HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerability

HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

πŸ“… Published: Dec. 16, 2025, 3:11 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 9:07 p.m.

0.0

CVE-2025-68262 - crypto: zstd - fix double-free in per-CPU stream cleanup

In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cleanup The crypto/zstd module has a double-free bug that occurs when multiple tfms are allocated and freed. The issue happens because zstd_streams (per-CPU contexts) are freed in…

πŸ“… Published: Dec. 16, 2025, 2:45 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

5.3

CVSS4.0

CVE-2025-14780 - Xiongwei Smart Catering Cloud Platform dish_trade_detail_get sql injection

A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now …

πŸ“… Published: Dec. 16, 2025, 1:02 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 2:29 p.m.

8.6

CVSS4.0

CVE-2025-65076 - Arbitrary File Read and Delete via Path Traversal in WaveStore Server

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in theΒ ilog script. This script is being run with root privile…

πŸ“… Published: Dec. 16, 2025, 12:25 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 7:11 p.m.
Total resulsts: 344032
Page 2053 of 34,404
Β« previous page Β» next page
Filters