8.6

CVSS4.0

CVE-2025-62173 - Authenticated SQL Injection in Endpoint Module Rest API

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

πŸ“… Published: Dec. 3, 2025, 11:14 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 10:07 p.m.

6.4

CVSS3.1

CVE-2025-66404 - mcp-server-kubernetes potential security issue in exec_in_pod tool

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string fo…

πŸ“… Published: Dec. 3, 2025, 8:40 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 7:07 p.m.

7.1

CVSS3.1

CVE-2025-66293 - LIBPNG has an out-of-bounds read in png_image_read_composite

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when proces…

πŸ“… Published: Dec. 3, 2025, 8:33 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 7:12 p.m.

4.6

CVSS4.0

CVE-2025-13086 - OpenVPN: OpenVPN: Improper validation of source IP addresses leads to denial of service

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

πŸ“… Published: Dec. 3, 2025, 7:54 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:38 p.m.

9.9

CVSS4.0

CVE-2025-66489 - Cal.com Authentication Bypass via bad TOTP + password checks

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in t…

πŸ“… Published: Dec. 3, 2025, 7:44 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 4:03 p.m.

7.1

CVSS4.0

CVE-2025-65097 - Insecure Direct Object Reference (IDOR) Allows Unauthorized Deletion of User Collections

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, an Authenticated User can delete collections belonging to other users by directly sending a DELETE request to the collection endpoint. No o…

πŸ“… Published: Dec. 3, 2025, 7:41 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2025-65096 - RomM Insecure Direct Object Reference (IDOR) Allows Unauthorized Access to Private Collections

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, users can read private collections / smart collections belonging to other users by directly accessing their IDs via API. No ownership verif…

πŸ“… Published: Dec. 3, 2025, 7:39 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:01 p.m.

8.7

CVSS4.0

CVE-2025-12385 - Improper validation of <img> tag size in Text component parser

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missi…

πŸ“… Published: Dec. 3, 2025, 7:38 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-61727 - Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

πŸ“… Published: Dec. 3, 2025, 7:37 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 8:15 p.m.

7.6

CVSS3.1

CVE-2025-65027 - RomM Chained XSS and CSRF Vulnerabilities Enable Admin Account Takeover

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious SVG or HTML files. When these files are accessed the brow…

πŸ“… Published: Dec. 3, 2025, 7:36 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:04 p.m.
Total resulsts: 344111
Page 2329 of 34,412
Β« previous page Β» next page
Filters