6.5

CVSS3.1

CVE-2025-67720 - Pyrofork has a Path Traversal in download_media Method

Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method before using them in file path construction. When downloading media, if the user does not specify a custom filename (…

πŸ“… Published: Dec. 11, 2025, 1:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-67719 - Ibexa User Bundle is missing password change validation

Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to run as expected. This …

πŸ“… Published: Dec. 11, 2025, 1:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-67718 - Formio improperly authorized permission elevation through specially crafted request path

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized reques…

πŸ“… Published: Dec. 11, 2025, 12:58 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-67717 - Zitadel Discloses the Total Number of Instance Users

ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, regardless of their specific permissions. While this does not leak individual user data or PII, disclosing the total…

πŸ“… Published: Dec. 11, 2025, 12:30 a.m. πŸ”„ Last Modified: Feb. 2, 2026, 3:10 p.m.

5.7

CVSS3.1

CVE-2025-67716 - Auth0 Next.js SDK has Improper Validation of Query Parameters

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query parameters into the Auth0 authorization request. Su…

πŸ“… Published: Dec. 11, 2025, 12:21 a.m. πŸ”„ Last Modified: March 6, 2026, 7:29 p.m.

5.3

CVSS4.0

CVE-2025-67713 - Miniflux 2 has an Open Redirect via protocol-relative `redirect_url`

Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like //ikotaslabs.com have an empty scheme and pass that check, allowing post-login redirects to attacker-…

πŸ“… Published: Dec. 11, 2025, 12:17 a.m. πŸ”„ Last Modified: Feb. 2, 2026, 3:05 p.m.

8.8

CVSS3.1

CVE-2025-56093 -

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Jan. 27, 2026, 5:52 p.m.

8.8

CVSS3.1

CVE-2025-56113 -

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:38 p.m.

8.8

CVSS3.1

CVE-2025-56107 -

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 26, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2025-56122 -

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

πŸ“… Published: Dec. 11, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 3:35 p.m.
Total resulsts: 346628
Page 2410 of 34,663
Β« previous page Β» next page
Filters