5

CVSS3.1

CVE-2025-67844 -

The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the specific GitHub App …

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:10 p.m.

6.5

CVSS3.1

CVE-2025-66911 -

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, an…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:49 p.m.

7.5

CVSS3.1

CVE-2025-66909 -

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java loads images using OpenCV's imread() function without validating dimensions or pixel count before decomp…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:50 p.m.

5.3

CVSS3.1

CVE-2025-66908 -

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR image upload functionality. The OcrController in turms-ai-serving/src/main/java/im/turms/ai/domain/ocr/controller/OcrController.java uses the @FormData(contentType = MediaTypeCons…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:57 p.m.

6.4

CVSS3.1

CVE-2025-67842 -

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:01 p.m.

6

CVSS3.1

CVE-2025-66910 -

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon successful login, ra…

πŸ“… Published: Dec. 19, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:50 p.m.

5.1

CVSS4.0

CVE-2025-14898 - CodeAstro Real Estate Management System Administrator Endpoint userbuilderdelete.php sql injection

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been…

πŸ“… Published: Dec. 18, 2025, 11:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

5.1

CVSS4.0

CVE-2025-14897 - CodeAstro Real Estate Management System Administrator Endpoint useragentdelete.php sql injection

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is pu…

πŸ“… Published: Dec. 18, 2025, 11:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:54 a.m.

8.3

CVSS3.1

CVE-2025-64675 - Azure Cosmos DB Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: Dec. 18, 2025, 11:15 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

9.1

CVSS3.1

CVE-2025-68398 - Weblate has git config file overwrite vulnerability that leads to remote code execution

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

πŸ“… Published: Dec. 18, 2025, 11 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 8:16 p.m.
Total resulsts: 349182
Page 2502 of 34,919
Β« previous page Β» next page
Filters