5.3

CVSS4.0

CVE-2025-15009 - liweiyi ChestnutCMS Filename upload FilenameUtils.getExtension unrestricted upload

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Filename Handler. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched …

πŸ“… Published: Dec. 22, 2025, 2:32 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 3:51 p.m.

6.9

CVSS4.0

CVE-2025-15008 - Tenda WH450 HTTP Request L7Port stack-based overflow

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public…

πŸ“… Published: Dec. 22, 2025, 2:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

9.3

CVSS4.0

CVE-2025-15007 - Tenda WH450 HTTP Request L7Im stack-based overflow

A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. …

πŸ“… Published: Dec. 22, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:02 a.m.

9.3

CVSS4.0

CVE-2025-15006 - Tenda WH450 HTTP Request CheckTools stack-based overflow

A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can be initiated remote…

πŸ“… Published: Dec. 22, 2025, 1:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

6.3

CVSS4.0

CVE-2025-15005 - CouchCMS reCAPTCHA config.example.php hard-coded key

A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key . It is po…

πŸ“… Published: Dec. 22, 2025, 12:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

5.3

CVSS4.0

CVE-2025-15004 - DedeCMS freelist_main.php sql injection

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 22, 2025, 12:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:01 a.m.

6.1

CVSS3.1

CVE-2025-67291 -

A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:41 p.m.

9.6

CVSS3.1

CVE-2025-67289 -

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:45 p.m.

4.3

CVSS3.1

CVE-2024-35321 -

MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 5:50 p.m.

4.7

CVSS3.1

CVE-2025-26787 -

An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certifi…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 5:48 p.m.
Total resulsts: 349182
Page 2481 of 34,919
Β« previous page Β» next page
Filters