8.7

CVSS4.0

CVE-2023-53734 - dawa-pharma-1.0 - SQL Injection via Email Parameter

dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.

๐Ÿ“… Published: Dec. 4, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.6

CVSS4.0

CVE-2025-27935 - Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

๐Ÿ“… Published: Dec. 4, 2025, 8:38 p.m. ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:27 p.m.

8.8

CVSS3.1

CVE-2025-13543 - PostGallery <= 1.12.5 - Authenticated (Subscriber+) Arbitrary File Upload

The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissioโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 8:27 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:36 p.m.

2.2

CVSS3.1

CVE-2025-12997 -

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: beforeโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 8:04 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 6:09 p.m.

4.1

CVSS3.1

CVE-2025-12996 -

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

๐Ÿ“… Published: Dec. 4, 2025, 8:04 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 6:09 p.m.

8.1

CVSS3.1

CVE-2025-12995 -

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

๐Ÿ“… Published: Dec. 4, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 6:09 p.m.

5.3

CVSS3.1

CVE-2025-12994 -

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.

๐Ÿ“… Published: Dec. 4, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 6:10 p.m.

8.5

CVSS3.1

CVE-2025-65958 - Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1โ€ฆ

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to acโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 7:55 p.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 3:18 p.m.

8.7

CVSS4.0

CVE-2025-12097 - Relative Path Traversal Vulnerability in NI System Web Server

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ย Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. ย This vulnerability eโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 7:07 p.m. ๐Ÿ”„ Last Modified: Feb. 25, 2026, 7:26 p.m.

7.5

CVSS3.1

CVE-2025-65945 - auth0/node-jws improper HMAC signature verification vulnerability

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:45 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 9:19 p.m.
Total resulsts: 343920
Page 2296 of 34,392
ยซ previous page ยป next page
Filters