2.7

CVSS3.1

CVE-2025-14082 - Keycloak-services: keycloak admin rest api: improper access control leads to sensitive role metadat…

A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 4:47 p.m.

4.3

CVSS3.1

CVE-2025-64056 -

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:18 a.m.

2.7

CVSS3.1

CVE-2025-14083 - Keycloak-server: keycloak: improper access control in admin rest api leads to information disclosure

A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 4:47 p.m.

9.6

CVSS3.1

CVE-2025-64054 -

A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:17 a.m.

7.2

CVSS3.1

CVE-2025-66644 -

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

5.1

CVSS3.1

CVE-2025-64052 -

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 1:10 a.m.

8.8

CVSS3.1

CVE-2025-65730 -

Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 6:01 p.m.

8.3

CVSS3.1

CVE-2025-64057 -

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:18 a.m.

8.1

CVSS3.1

CVE-2025-65879 -

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authen…

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:51 p.m.

8.7

CVSS4.0

CVE-2025-13373 - Advantech iView SQL Injection

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

πŸ“… Published: Dec. 4, 2025, 10:50 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:27 p.m.
Total resulsts: 344111
Page 2310 of 34,412
Β« previous page Β» next page
Filters