7.5

CVSS3.1

CVE-2025-65564 -

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:03 p.m.

7.5

CVSS3.1

CVE-2025-63757 - ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 8:04 p.m.

0.0

CVE-2025-68325 - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc w…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-67163 -

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:58 p.m.

7.5

CVSS3.1

CVE-2025-65562 -

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNod…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:01 p.m.

8.2

CVSS4.0

CVE-2025-14202 - Cross-Site Request Forgery (CSRF) Leading to Account Takeover via SVG File Upload

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the admin’s browser, retr…

πŸ“… Published: Dec. 17, 2025, 11:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-14837 - ZZCMS Backend Website Settings siteconfig.php stripfxg code injection

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website Settings Module. Such manipulation of the argument icp leads to code injection. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Dec. 17, 2025, 11:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:53 a.m.

9.1

CVSS3.1

CVE-2025-68435 - Zerobyte has Authentication Bypass by Primary Weakness

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This i…

πŸ“… Published: Dec. 17, 2025, 11:10 p.m. πŸ”„ Last Modified: March 5, 2026, 7:30 p.m.

5.1

CVSS4.0

CVE-2025-14836 - ZZCMS User Data Storage user_save.php cleartext storage in file

A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has b…

πŸ“… Published: Dec. 17, 2025, 11:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:52 a.m.

5.3

CVSS4.0

CVE-2025-14834 - code-projects Simple Stock System checkuser.php sql injection

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public a…

πŸ“… Published: Dec. 17, 2025, 11:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.
Total resulsts: 349182
Page 2542 of 34,919
Β« previous page Β» next page
Filters