4.3

CVSS3.1

CVE-2025-13372 - Potential SQL injection in FilteredRelation column aliases on PostgreSQL

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on Postgre…

📅 Published: Dec. 2, 2025, 3:13 p.m. 🔄 Last Modified: Dec. 12, 2025, 12:57 p.m.

4.8

CVSS4.0

CVE-2025-13876 - Rareprob HD Video Player All Formats App com.rocks.music.videoplayer path traversal

A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component com.rocks.music.videoplayer. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclose…

📅 Published: Dec. 2, 2025, 3:02 p.m. 🔄 Last Modified: Feb. 26, 2026, 11:30 p.m.

5.3

CVSS4.0

CVE-2025-13875 - Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal

A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI Configuration Upload. Executing manipulation of the argument File can lead to path travers…

📅 Published: Dec. 2, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 4, 2025, 6:07 p.m.

4.8

CVSS3.1

CVE-2025-13505 - Stored XSS in Datateam's Datactive

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Datateam Information Technologies Inc. Datactive allows Stored XSS.This issue affects Datactive: from 2.13.34 b…

📅 Published: Dec. 2, 2025, 2:22 p.m. 🔄 Last Modified: Jan. 30, 2026, 8:32 p.m.

6.9

CVSS4.0

CVE-2025-41066 - Disclosure of sensitive information in Horde Groupware

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vulnerability, an HTTP request must be sent to ‘/imp/attachment.php’ including the parameters ‘id’ and ‘u’. If the specifie…

📅 Published: Dec. 2, 2025, 2:01 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:08 p.m.

6.4

CVSS3.1

CVE-2025-13731 - Nexter Extension <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a…

📅 Published: Dec. 2, 2025, 1:53 p.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

7.5

CVSS3.1

CVE-2025-13295 - Sensitive Data Exposure in ArgusTech's BILGER

Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message Identifier.This issue affects BILGER: before 2.4.9.

📅 Published: Dec. 2, 2025, 1:43 p.m. 🔄 Last Modified: Feb. 12, 2026, 5:30 p.m.

6.9

CVSS4.0

CVE-2025-41086 - Authorization bypass in GAMS from GAMS Development Corp.

Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate …

📅 Published: Dec. 2, 2025, 1:22 p.m. 🔄 Last Modified: Feb. 3, 2026, 5:19 p.m.

6.9

CVSS4.0

CVE-2025-41015 - User Enumeration vulnerability in TCMAN GIM

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetUserQuestionAndAnswer' in '/WS/PDAWebSe…

📅 Published: Dec. 2, 2025, 1:18 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:08 p.m.

6.9

CVSS4.0

CVE-2025-41014 - User Enumeration vulnerability in TCMAN GIM

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebS…

📅 Published: Dec. 2, 2025, 1:18 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:07 p.m.
Total resulsts: 343948
Page 2327 of 34,395
« previous page » next page
Filters