8.2

CVSS3.1

CVE-2025-65781 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS …

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:35 a.m.

8.1

CVSS3.1

CVE-2025-65778 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token thef…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:44 a.m.

2.5

CVSS3.1

CVE-2025-55703 -

An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outdated API endpoint that applied arrays without proper input validation. This can allow attackers to manipulate SQL queries. This has been addressed in Power IQ version 9.2.1, where…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 8:28 p.m.

8.8

CVSS3.1

CVE-2025-60786 -

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:05 p.m.

5.4

CVSS3.1

CVE-2025-65431 -

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:08 p.m.

6.5

CVSS3.1

CVE-2025-65782 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vo…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:08 p.m.

9.8

CVSS3.1

CVE-2025-66440 -

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the to…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:23 p.m.

9.1

CVSS3.1

CVE-2025-66844 -

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 3:38 p.m.

8.3

CVSS3.1

CVE-2024-44599 -

FNT Command 13.4.0 is vulnerable to Directory Traversal.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:06 p.m.

7.5

CVSS3.1

CVE-2025-65779 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:39 a.m.
Total resulsts: 343887
Page 2084 of 34,389
Β« previous page Β» next page
Filters