9.8

CVSS3.1

CVE-2025-63389 -

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 22, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-63387 -

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous a…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 22, 2026, 8:16 p.m.

0.0

CVE-2025-68323 - usb: typec: ucsi: fix use-after-free caused by uec->work

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->work is scheduled in gaokun_ucsi_probe() but never properly canceled in gaokun_ucsi_remove(). This creates use-after-free scenarios where the ucsi and…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-56157 -

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:03 p.m.

7.5

CVSS3.1

CVE-2025-65568 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsi…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:06 p.m.

7.5

CVSS3.1

CVE-2025-63951 -

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:27 p.m.

7.5

CVSS3.1

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:32 p.m.

5.4

CVSS3.1

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:36 p.m.

5.4

CVSS3.1

CVE-2025-63947 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 9:15 p.m.
Total resulsts: 349182
Page 2540 of 34,919
Β« previous page Β» next page
Filters