7.2

CVSS3.1

CVE-2025-68460 - roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

πŸ“… Published: Dec. 18, 2025, 4:54 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 4:25 p.m.

6.4

CVSS3.1

CVE-2025-12885 - Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: Dec. 18, 2025, 1:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-14856 - y_project RuoYi getnames code injection

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicl…

πŸ“… Published: Dec. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

4.8

CVSS4.0

CVE-2025-14841 - OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null point…

πŸ“… Published: Dec. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-68324 - scsi: imm: Fix use-after-free bug caused by unfinished delayed work

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-63389 -

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 22, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-63387 -

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous a…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 22, 2026, 8:16 p.m.

0.0

CVE-2025-68323 - usb: typec: ucsi: fix use-after-free caused by uec->work

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->work is scheduled in gaokun_ucsi_probe() but never properly canceled in gaokun_ucsi_remove(). This creates use-after-free scenarios where the ucsi and…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-56157 -

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:03 p.m.
Total resulsts: 346481
Page 2270 of 34,649
Β« previous page Β» next page
Filters