6.1

CVSS3.1

CVE-2025-67443 -

Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:56 p.m.

6.1

CVSS3.1

CVE-2025-67290 -

A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:43 p.m.

10

CVSS3.1

CVE-2025-67288 -

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is …

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 6:15 p.m.

9.8

CVSS3.1

CVE-2025-67418 -

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative co…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:39 p.m.

9.8

CVSS3.1

CVE-2025-65856 -

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical e…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:28 p.m.

6.1

CVSS3.1

CVE-2025-65270 -

Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 5:51 p.m.

6.1

CVSS3.1

CVE-2024-25814 -

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:29 p.m.

6.1

CVSS3.1

CVE-2024-25812 -

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:29 p.m.

0.0

CVE-2025-68332 - comedi: c6xdigio: Fix invalid PNP driver unregistration

In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistration The Comedi low-level driver "c6xdigio" seems to be for a parallel port connected device. When the Comedi core calls the driver's Comedi "attach" handler `c6xdigio_attach()`…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-68645 -

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influe…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.
Total resulsts: 349182
Page 2484 of 34,919
Β« previous page Β» next page
Filters