5

CVSS3.1

CVE-2025-68944 - gitea: Gitea: Access control bypass in package registries

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

๐Ÿ“… Published: Dec. 26, 2025, 3:37 a.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 10:30 p.m.

5.3

CVSS3.1

CVE-2025-68943 - gitea: Gitea: Information disclosure of user login times via sort order

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

๐Ÿ“… Published: Dec. 26, 2025, 3:19 a.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 10:31 p.m.

5.3

CVSS4.0

CVE-2025-15098 - YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/header/body can lead to server-side request forgery. The attack mayโ€ฆ

๐Ÿ“… Published: Dec. 26, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-68942 - gitea: Gitea: Cross-Site Scripting (XSS) vulnerability via search input

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

๐Ÿ“… Published: Dec. 26, 2025, 2:50 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 7:31 p.m.

6.9

CVSS4.0

CVE-2025-15097 - Alteryx Server status improper authentication

A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipulation results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrโ€ฆ

๐Ÿ“… Published: Dec. 26, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-68941 - gitea: Gitea: Unauthorized access to private resources via public-scoped API tokens

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

๐Ÿ“… Published: Dec. 26, 2025, 2:31 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 7:33 p.m.

3.1

CVSS3.1

CVE-2025-68940 - gitea: Gitea: Unauthorized branch deletion due to inadequate permission enforcement

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

๐Ÿ“… Published: Dec. 26, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 7:33 p.m.

8.2

CVSS3.1

CVE-2025-68939 - gitea: attachments can be renamed to forbidden file extensions via the attachment API

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

๐Ÿ“… Published: Dec. 26, 2025, 2:03 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 7:35 p.m.

5.1

CVSS4.0

CVE-2025-15095 - postmanlabs httpbin core.py cross site scripting

A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. โ€ฆ

๐Ÿ“… Published: Dec. 26, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15094 - sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can โ€ฆ

๐Ÿ“… Published: Dec. 26, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.
Total resulsts: 347394
Page 2223 of 34,740
ยซ previous page ยป next page
Filters