1.3

CVSS4.0

CVE-2025-66622 - matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values

matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room withโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:07 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 8:27 p.m.

9.3

CVSS4.0

CVE-2025-66568 - ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrappingโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:03 a.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 9:25 p.m.

9.3

CVSS4.0

CVE-2025-66567 - ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different documeโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:55 a.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 9:27 p.m.

9.3

CVSS4.0

CVE-2025-66565 - Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:47 a.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 4:35 p.m.

6.5

CVSS3.1

CVE-2025-66508 - 1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (TrustedProxies = 0.0.0.0/0), allowing any client to spoof the X-Forwarded-For header. Since all IP-based access controlsโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:37 a.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 9:28 p.m.

6.9

CVSS4.0

CVE-2025-14286 - Tenda AC9 Configuration File DownloadCfg.jpg information disclosure

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The explโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 5:45 a.m.

7.5

CVSS3.1

CVE-2025-66507 - 1Panel โ€“ CAPTCHA Bypass via Client-Controlled Flag

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA prโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:25 a.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 9:28 p.m.

6.9

CVSS4.0

CVE-2025-14285 - code-projects Employee Profile Management System edit_personnel.php sql injection

A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in sql injection. The attack can be launched remotely. The exploit has been made public and could be useโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 5:45 a.m.

5.9

CVSS3.1

CVE-2025-66491 - Traefik has Inverted TLS Verification Logic in its ingress-nginx Provider

Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backend TLS certificate verification) actually disables verificatโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 9:12 p.m.

6.9

CVSS4.0

CVE-2025-66490 - Traefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules

Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests using PathPrefix, Path or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containing URL-encoded restricted characters (/, \, Null, โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: March 6, 2026, 3:25 p.m.
Total resulsts: 345151
Page 2346 of 34,516
ยซ previous page ยป next page
Filters