10

CVSS3.1

CVE-2025-66209 - Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrar…

📅 Published: Dec. 23, 2025, 9:42 p.m. 🔄 Last Modified: March 17, 2026, 5:16 p.m.

7.8

CVSS3.1

CVE-2025-12840 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:46 p.m.

7.8

CVSS3.1

CVE-2025-12839 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:45 p.m.

7.8

CVSS3.1

CVE-2025-12495 - Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executi…

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vu…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: Jan. 15, 2026, 4:45 p.m.

7.3

CVSS3.0

CVE-2025-12838 - MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability

MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp…

📅 Published: Dec. 23, 2025, 9:41 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.0

CVE-2025-13698 - Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability

Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific fl…

📅 Published: Dec. 23, 2025, 9:40 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.0

CVE-2025-13715 - Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerabi…

Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent FaceDetection-DSFD. User interaction is required to exploit this vulnerability in that t…

📅 Published: Dec. 23, 2025, 9:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.0

CVE-2025-13709 - Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerabil…

Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must…

📅 Published: Dec. 23, 2025, 9:34 p.m. 🔄 Last Modified: Jan. 12, 2026, 5:37 p.m.

7.8

CVSS3.0

CVE-2025-13711 - Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability

Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must visit a malic…

📅 Published: Dec. 23, 2025, 9:34 p.m. 🔄 Last Modified: Jan. 12, 2026, 5:36 p.m.

7.8

CVSS3.0

CVE-2025-13706 - Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulner…

Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent PatrickStar. User interaction is required to exploit this vulnerability in that the t…

📅 Published: Dec. 23, 2025, 9:34 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2459 of 34,919
« previous page » next page
Filters