3.1

CVSS3.0

CVE-2025-8850 - Insecure API Design in danny-avila/librechat

In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a valid OTP or backup code, bypassing the intended verification process. This vulnerability occurs because the backend do…

πŸ“… Published: Oct. 30, 2025, 7:59 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.6

CVSS3.1

CVE-2025-3356 - IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.

πŸ“… Published: Oct. 30, 2025, 7:22 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:10 a.m.

7.5

CVSS3.1

CVE-2025-3355 - IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

πŸ“… Published: Oct. 30, 2025, 7:21 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 1:58 a.m.

7.2

CVSS3.1

CVE-2025-36137 - IBM Sterling Connect:Direct for UNIX command execution

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges fur…

πŸ“… Published: Oct. 30, 2025, 6:53 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

4.8

CVSS4.0

CVE-2025-62265 -

Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allow…

πŸ“… Published: Oct. 30, 2025, 6:30 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 1:58 a.m.

6.1

CVSS4.0

CVE-2025-64118 - node-tar vulnerable to race condition leading to uninitialized memory exposure

node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.

πŸ“… Published: Oct. 30, 2025, 5:50 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8

CVSS3.1

CVE-2025-64112 - Statmatic vulnerable to Stored Cross-Site Scripting

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fix…

πŸ“… Published: Oct. 30, 2025, 5:47 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

0.0

CVE-2025-64338 -

This CVE is a duplicate of another CVE.

πŸ“… Published: Oct. 30, 2025, 5:40 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 4:47 a.m.

5.1

CVSS4.0

CVE-2025-64115 - Movary unvalidated Referer header allows open redirect and phishing

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in multiple settings endpoints, allowing a crafted link to cause an open redirect to an attacker-controlled site and facilita…

πŸ“… Published: Oct. 30, 2025, 5:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.1

CVSS4.0

CVE-2025-62266 -

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows …

πŸ“… Published: Oct. 30, 2025, 5:37 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 1:58 a.m.
Total resulsts: 318415
Page 208 of 31,842
Β« previous page Β» next page
Filters