9.1

CVSS3.1

CVE-2025-55895 -

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:21 p.m.

5.3

CVSS3.1

CVE-2023-38913 -

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:33 p.m.

8.8

CVSS3.1

CVE-2025-66437 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a str…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:19 p.m.

5.5

CVSS3.1

CVE-2025-66963 -

An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:05 p.m.

9.8

CVSS3.1

CVE-2025-66434 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a cust…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 5:57 p.m.

5.3

CVSS3.1

CVE-2023-36338 -

Inventory Management System 1 was discovered to contain a SQL injection vulnerability.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:32 p.m.

5.4

CVSS3.1

CVE-2025-66843 -

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later exe…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 3:39 p.m.

5.4

CVSS3.1

CVE-2025-65430 -

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 7:02 p.m.

8.8

CVSS3.1

CVE-2025-65780 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privileg…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:37 a.m.

9.8

CVSS3.1

CVE-2025-65213 -

MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled file paths without validation, allowing arbitrary code executi…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 8:51 p.m.
Total resulsts: 343887
Page 2085 of 34,389
Β« previous page Β» next page
Filters