2.1

CVSS4.0

CVE-2025-61594 - URI Credential Leakage Bypass over CVE-2025-27221

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information lik…

πŸ“… Published: Dec. 30, 2025, 9:03 p.m. πŸ”„ Last Modified: April 20, 2026, 3:45 p.m.

5.3

CVSS4.0

CVE-2025-15357 - D-Link DI-7400G+ msp_info.htm command injection

A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.

πŸ“… Published: Dec. 30, 2025, 9:02 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:35 p.m.

8.7

CVSS4.0

CVE-2025-15356 - Tenda AC20 PowerSaveSet sscanf buffer overflow

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer overflow. The attack can be initiated remotely. The exploit h…

πŸ“… Published: Dec. 30, 2025, 8:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:19 a.m.

1.3

CVSS4.0

CVE-2025-14986 - ExecuteMultiOperation Namespace Policy Bypass

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized…

πŸ“… Published: Dec. 30, 2025, 8:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-14987 - Cross Namespace Commands Authorization Bypass

When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a different namespace than the namespace authorized a…

πŸ“… Published: Dec. 30, 2025, 8:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15354 - itsourcecode Society Management System add_admin.php sql injection

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published …

πŸ“… Published: Dec. 30, 2025, 8:02 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

5.5

CVSS4.0

CVE-2025-69261 - WasmEdge integer wrap in MemoryInstance::getSpan()'s memory size check

WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.

πŸ“… Published: Dec. 30, 2025, 7:43 p.m. πŸ”„ Last Modified: March 9, 2026, 1:55 p.m.

6.9

CVSS4.0

CVE-2025-15353 - itsourcecode Society Management System edit_admin_query.php edit_admin_query sql injection

A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of the file /admin/edit_admin_query.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is no…

πŸ“… Published: Dec. 30, 2025, 7:32 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

1.2

CVSS4.0

CVE-2025-69210 - FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. Authenticated users can upload crafted XML files containing executable JavaScript. These fi…

πŸ“… Published: Dec. 30, 2025, 7:23 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 3:23 p.m.

6.7

CVSS3.1

CVE-2025-69257 - theshit vulnerable to unsafe loading of user-owned Python rules when running as root.

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.config/theshit/`) without validating ownership or permissions w…

πŸ“… Published: Dec. 30, 2025, 7:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347810
Page 2203 of 34,781
Β« previous page Β» next page
Filters