6.3

CVSS4.0

CVE-2025-66204 - WBCE CMS allows brute-force protection bypass using X-Forwarded-For header

WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attempts, effectively bypassing all brute-force protection. The ap…

πŸ“… Published: Dec. 8, 2025, 11:50 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 4:02 p.m.

6.5

CVSS3.1

CVE-2025-66202 - Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, t…

πŸ“… Published: Dec. 8, 2025, 11:41 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 11:46 p.m.

9.4

CVSS4.0

CVE-2025-65964 - n8n Vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation allows workflows to set arbitrary Git configuration values, including core.hooksPath, which can point…

πŸ“… Published: Dec. 8, 2025, 11:35 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 9:10 p.m.

4.6

CVSS3.1

CVE-2025-65962 - Tuleap has missing CSRF protections its in tracker field dependencies

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap Enterprise Edition versions prior to 17.0-4 and 16.13-9 are mission CSRF protections in its tracker field dependencies, allowi…

πŸ“… Published: Dec. 8, 2025, 11:15 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 11:49 p.m.

4.6

CVSS3.1

CVE-2025-64760 - Tuleap has missing CSRF protections in its tracker trigger management system

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker…

πŸ“… Published: Dec. 8, 2025, 11:08 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:01 p.m.

4.6

CVSS3.1

CVE-2025-64499 - Tuleap is missing CSRF protections for its planning management API

Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. …

πŸ“… Published: Dec. 8, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:03 p.m.

4.6

CVSS3.1

CVE-2025-64498 - Tuleap has a Cross-Site Request Forgery (CSRF) vulnerability

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. Thi…

πŸ“… Published: Dec. 8, 2025, 10:36 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:04 p.m.

6.5

CVSS3.1

CVE-2025-64497 - Tuleap exposes releases for all projects to File Release System project administrators

Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not …

πŸ“… Published: Dec. 8, 2025, 10:28 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 9:10 p.m.

6.5

CVSS3.1

CVE-2025-36140 - IBM watsonx.data Denial of Service

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits.

πŸ“… Published: Dec. 8, 2025, 10:11 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 7:56 p.m.

5.9

CVSS3.1

CVE-2025-62408 - c-ares has a Use After Free vulnerability when connection is cleaned up after error

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

πŸ“… Published: Dec. 8, 2025, 10:04 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 2:40 p.m.
Total resulsts: 346560
Page 2505 of 34,656
Β« previous page Β» next page
Filters