6.1

CVSS3.1

CVE-2025-67708 - Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:17 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:04 p.m.

5.6

CVSS3.1

CVE-2025-67707 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls that restrict uploaded …

📅 Published: Dec. 31, 2025, 10:16 p.m. 🔄 Last Modified: Feb. 20, 2026, 2:48 p.m.

5.6

CVSS3.1

CVE-2025-67706 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls that restrict uploaded …

📅 Published: Dec. 31, 2025, 10:15 p.m. 🔄 Last Modified: Feb. 19, 2026, 9:29 p.m.

6.1

CVSS3.1

CVE-2025-67705 - Reflected XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:15 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2025-67704 - Stored XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:14 p.m.

6.1

CVSS3.1

CVE-2025-67703 - Stored XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:13 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:15 p.m.

6.3

CVSS4.0

CVE-2025-15398 - Uasoft badaso Token BadasoAuthController.php forgetPassword password recovery

A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The attack can be executed remotely. This attack i…

📅 Published: Dec. 31, 2025, 10:02 p.m. 🔄 Last Modified: Jan. 14, 2026, 8:36 p.m.

9.1

CVSS3.1

CVE-2025-69288 - Titra has Remote Code Execution in Admin Functionality

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.9…

📅 Published: Dec. 31, 2025, 9:55 p.m. 🔄 Last Modified: Jan. 13, 2026, 3:25 p.m.

8.9

CVSS4.0

CVE-2025-69286 - RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens a…

📅 Published: Dec. 31, 2025, 9:52 p.m. 🔄 Last Modified: Jan. 6, 2026, 4:47 p.m.

7.1

CVSS4.0

CVE-2023-7332 - PocketMine-MP < 4.18.1 Improper Validation of Dropped Item Count Allows Remote Server Crash

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting i…

📅 Published: Dec. 31, 2025, 9:37 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347632
Page 2160 of 34,764
« previous page » next page
Filters