5.5

CVSS4.0

CVE-2025-58044 - JumpServer has an Open Redirect Vulnerability

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerabil…

πŸ“… Published: Dec. 1, 2025, 8:17 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 7:48 p.m.

8.7

CVSS4.0

CVE-2025-55749 - The XWiki Jetty package (XJetty) allows accessing any application file through URL

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. F…

πŸ“… Published: Dec. 1, 2025, 8:09 p.m. πŸ”„ Last Modified: March 2, 2026, 10:02 p.m.

4.3

CVSS3.1

CVE-2025-12756 - Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.

πŸ“… Published: Dec. 1, 2025, 7:51 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:26 p.m.

6.6

CVSS3.1

CVE-2025-11772 - Co-Installer Privilege Escalation

A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.

πŸ“… Published: Dec. 1, 2025, 6:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-34297 - KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)), which can wrap to a small value when …

πŸ“… Published: Dec. 1, 2025, 6:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.1

CVSS4.0

CVE-2025-13837 - Out-of-memory when loading Plist

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

πŸ“… Published: Dec. 1, 2025, 6:13 p.m. πŸ”„ Last Modified: March 3, 2026, 3:16 p.m.

6.3

CVSS4.0

CVE-2025-13836 - Excessive read buffering DoS in http.client

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

πŸ“… Published: Dec. 1, 2025, 6:02 p.m. πŸ”„ Last Modified: March 3, 2026, 2:41 p.m.

4.3

CVSS3.1

CVE-2025-13653 - Unauthorized access to documents in data streams with specially crafted requests

In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.

πŸ“… Published: Dec. 1, 2025, 6:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-13835 - WordPress Arconix Shortcodes plugin <= 2.1.20 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.20.

πŸ“… Published: Dec. 1, 2025, 5:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-13832 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Dec. 1, 2025, 5:03 p.m. πŸ”„ Last Modified: Dec. 13, 2025, 10:19 p.m.
Total resulsts: 344974
Page 2446 of 34,498
Β« previous page Β» next page
Filters