7.4

CVSS4.0

CVE-2025-66238 - Sunbird DCIM dcTrack and Power IQ Authentication Bypass Using an Alternate Path or Channel

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

πŸ“… Published: Dec. 4, 2025, 9:10 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:27 p.m.

0.0

CVE-2025-14066 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Dec. 4, 2025, 9:03 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 10:19 p.m.

8.4

CVSS4.0

CVE-2025-66237 - Sunbird DCIM dcTrack and Power IQ Use of Hard-coded Credentials

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

πŸ“… Published: Dec. 4, 2025, 9:02 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:27 p.m.

1.8

CVSS4.0

CVE-2025-66479 - Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sa…

πŸ“… Published: Dec. 4, 2025, 8:57 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:27 p.m.

8.7

CVSS3.1

CVE-2025-65959 - Open WebUI vulnerable to Stored DOM XSS via Note 'Download PDF'

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing t…

πŸ“… Published: Dec. 4, 2025, 8:46 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 3:35 p.m.

8.9

CVSS4.0

CVE-2025-66576 - Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

πŸ“… Published: Dec. 4, 2025, 8:46 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

8.5

CVSS4.0

CVE-2025-66575 - VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

πŸ“… Published: Dec. 4, 2025, 8:46 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 4:33 p.m.

5.3

CVSS4.0

CVE-2025-66574 - TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS)

TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.

πŸ“… Published: Dec. 4, 2025, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

6.9

CVSS4.0

CVE-2025-66573 - Solstice Pod API Session Key Extraction via API Endpoint

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without auth…

πŸ“… Published: Dec. 4, 2025, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

6.9

CVSS4.0

CVE-2025-66572 - Loaded Commerce 6.6 Client-Side Template Injection(CSTI)

Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute code on the server via the search parameter.

πŸ“… Published: Dec. 4, 2025, 8:44 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.
Total resulsts: 343887
Page 2291 of 34,389
Β« previous page Β» next page
Filters