4.8

CVSS4.0

CVE-2025-15202 - SohuTV CacheCloud TaskController.java taskQueueList cross site scripting

A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclo…

📅 Published: Dec. 29, 2025, 7:32 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:36 p.m.

6

CVSS4.0

CVE-2025-14175 - Weak Algorithm Support in SSH Server on TL-WR820N

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.

📅 Published: Dec. 29, 2025, 7:31 p.m. 🔄 Last Modified: March 8, 2026, 1:49 a.m.

6

CVSS4.0

CVE-2025-69202 - axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring…

📅 Published: Dec. 29, 2025, 7:13 p.m. 🔄 Last Modified: Jan. 5, 2026, 8:05 p.m.

6.5

CVSS3.1

CVE-2025-68431 - libheif has Potential Heap Buffer Over-Read

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or…

📅 Published: Dec. 29, 2025, 7:09 p.m. 🔄 Last Modified: Feb. 25, 2026, 2:53 p.m.

6.8

CVSS3.1

CVE-2025-14728 - Rapid7 Velociraptor Directory Traversal Vulnerability

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficie…

📅 Published: Dec. 29, 2025, 7:04 p.m. 🔄 Last Modified: Feb. 20, 2026, 7:37 p.m.

5.1

CVSS4.0

CVE-2025-15201 - SohuTV CacheCloud WebResourceController.java redirectNoPower cross site scripting

A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file src/main/java/com/sohu/cache/web/controller/WebResourceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The expl…

📅 Published: Dec. 29, 2025, 7:02 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:37 p.m.

4.8

CVSS4.0

CVE-2025-15200 - SohuTV CacheCloud AppClientDataShowController.java doIndex cross site scripting

A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisticsByClient/getCommandStatisticsByClient/doIndex of the file src/main/java/com/sohu/cache/web/controller/AppClientDataShowController.java. The manipulation results in cross site sc…

📅 Published: Dec. 29, 2025, 6:32 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:38 p.m.

7.2

CVSS3.1

CVE-2025-13592 - Advanced Ads <= 2.0.14 - Authenticated (Editor+) Remote Code Execution via Shortcode

The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This allows authenticated attackers with editor-level permissions or above, to execute code on the server.

📅 Published: Dec. 29, 2025, 6:20 p.m. 🔄 Last Modified: April 21, 2026, 12:45 a.m.

5.3

CVSS3.1

CVE-2025-14280 - PixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log File

The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.1.5 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files, …

📅 Published: Dec. 29, 2025, 6:20 p.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2025-15199 - code-projects College Notes Uploading System userprofile.php unrestricted upload

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboard/userprofile.php. The manipulation of the argument image leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has…

📅 Published: Dec. 29, 2025, 6:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 6:12 a.m.
Total resulsts: 346536
Page 2118 of 34,654
« previous page » next page
Filters