6.9

CVSS4.0

CVE-2025-66415 - fastify-reply-from bypass of reply forwarding

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:39 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 4:56 p.m.

8.5

CVSS4.0

CVE-2025-66412 - Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the coโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:35 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 4:37 p.m.

8.7

CVSS4.0

CVE-2025-66410 - Gin-vue-admin has an arbitrary file deletion vulnerability

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.

๐Ÿ“… Published: Dec. 1, 2025, 10:28 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 4:50 p.m.

6.9

CVSS4.0

CVE-2025-66405 - Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. Thiโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:25 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:21 p.m.

4.6

CVSS3.1

CVE-2025-66403 - FileRise Vulnerable to Stored XSS via SVG Upload

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG files. The application accepts user-supplied SVG uploโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:20 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 8:50 p.m.

6.9

CVSS4.0

CVE-2025-66400 - mdast-util-to-hast unsanitized class attribute

mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerabiโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 4:36 p.m.

5.1

CVSS4.0

CVE-2025-66313 - ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter

ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value is incorporated into a SQL query without proper paโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:13 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 5:58 p.m.

6.2

CVSS4.0

CVE-2025-66312 - Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/โ€ฆ

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/groups/Grupo endpoint of the Grav application. Thโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:06 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 9:56 p.m.

6.2

CVSS4.0

CVE-2025-66311 - Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples paโ€ฆ

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:05 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 9:56 p.m.

6.2

CVSS4.0

CVE-2025-66310 - Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `dataโ€ฆ

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerโ€ฆ

๐Ÿ“… Published: Dec. 1, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 9:56 p.m.
Total resulsts: 343923
Page 2338 of 34,393
ยซ previous page ยป next page
Filters