7.5

CVSS3.1

CVE-2025-65561 -

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 7, 2026, 9 p.m.

7.5

CVSS3.1

CVE-2025-65566 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Session Report Response that is missing the mandatory Cause Information Element, the session report handler dereferences a nil pointer instead โ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 4:18 p.m.

7.5

CVSS3.1

CVE-2025-65565 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. Tโ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 7, 2026, 9:06 p.m.

9.1

CVSS3.1

CVE-2025-63386 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains tโ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 11, 2026, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-63391 -

An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 22, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-65559 -

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4โ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 8:01 p.m.

5.3

CVSS3.1

CVE-2025-63390 -

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. Exposed daโ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 22, 2026, 6:16 p.m.

6.1

CVSS3.1

CVE-2025-63949 -

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 7:35 p.m.

9.1

CVSS3.1

CVE-2025-63388 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any extโ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 28, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-65567 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flโ€ฆ

๐Ÿ“… Published: Dec. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 7, 2026, 9:06 p.m.
Total resulsts: 349182
Page 2541 of 34,919
ยซ previous page ยป next page
Filters