6.9

CVSS4.0

CVE-2025-68948 - SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is…

πŸ“… Published: Dec. 27, 2025, 12:21 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:30 p.m.

7.3

CVSS4.0

CVE-2025-68927 - Improper Neutralization of HTML Tags in a Web Page in libredesk

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the …

πŸ“… Published: Dec. 27, 2025, 12:04 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 2:32 p.m.

10

CVSS3.1

CVE-2025-54322 -

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

πŸ“… Published: Dec. 27, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:33 p.m.

6.1

CVSS4.0

CVE-2025-68474 - ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRC_MIN_CMD_LEN (20 bytes). However, the actual…

πŸ“… Published: Dec. 26, 2025, 11:57 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4 p.m.

0

CVSS4.0

CVE-2025-68473 - ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[32][MAX_UUID_SIZE] to store discovered service UUI…

πŸ“… Published: Dec. 26, 2025, 11:54 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4:01 p.m.

4.3

CVSS3.1

CVE-2025-68148 - FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After

FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in versio…

πŸ“… Published: Dec. 26, 2025, 11:46 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:16 p.m.

2.9

CVSS4.0

CVE-2025-68932 - FreshRSS has weak cryptographic randomness in remember-me token and nonce generation

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, leadi…

πŸ“… Published: Dec. 26, 2025, 11:43 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:12 p.m.

10

CVSS3.1

CVE-2025-66203 - StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration …

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without s…

πŸ“… Published: Dec. 26, 2025, 11:37 p.m. πŸ”„ Last Modified: March 9, 2026, 1:41 p.m.

8.8

CVSS3.1

CVE-2025-67729 - lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoint files. This allows an attacker to execute arbi…

πŸ“… Published: Dec. 26, 2025, 9:54 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:31 p.m.

7.1

CVSS3.1

CVE-2025-68697 - Self-hosted n8n has Legacy Code node that enables arbitrary file read/write

n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke internal helper functions from within the Code node. T…

πŸ“… Published: Dec. 26, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:27 p.m.
Total resulsts: 347398
Page 2220 of 34,740
Β« previous page Β» next page
Filters