9.9

CVSS4.0

CVE-2025-68667 - Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue

Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated attacker to force the target server to cryptographically sign arbitrary membership events. Affected products include Conduit prior to version 0.10.10, coโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-68617 - Use after free in fluidsynth

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading to use of freed memoโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:41 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 2:01 a.m.

6.9

CVSS4.0

CVE-2025-15048 - Tenda WH450 HTTP Request CheckTools command injection

A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

9.4

CVSS4.0

CVE-2025-66213 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Dirโ€ฆ

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users with application/service management permissions tโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:06 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 5:16 p.m.

9.4

CVSS4.0

CVE-2025-66212 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Coโ€ฆ

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users with application/service management permissions to โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 5:16 p.m.

9.3

CVSS4.0

CVE-2025-15047 - Tenda WH450 HTTP Request PPTPDClient stack-based overflow

A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit hasโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

9.4

CVSS4.0

CVE-2025-66211 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init โ€ฆ

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with application/service management permissions to execute aโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 10 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 5:16 p.m.

9.4

CVSS4.0

CVE-2025-66210 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/service management permissions to execute arbitrarโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 9:49 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 5:16 p.m.

7.5

CVSS3.0

CVE-2025-12491 - Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability

Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 9:43 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.0

CVE-2025-13700 - DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementatiโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, 9:42 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2458 of 34,919
ยซ previous page ยป next page
Filters