0.0

CVE-2025-40346 - arch_topology: Fix incorrect error check in topology_parse_cpu_capacity()

In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() Fix incorrect use of PTR_ERR_OR_ZERO() in topology_parse_cpu_capacity() which causes the code to proceed with NULL clock pointers. The current logic uses !…

📅 Published: Dec. 16, 2025, 1:30 p.m. 🔄 Last Modified: Dec. 16, 2025, 1:30 p.m.

5.3

CVSS4.0

CVE-2025-14780 - Xiongwei Smart Catering Cloud Platform dish_trade_detail_get sql injection

A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now …

📅 Published: Dec. 16, 2025, 1:02 p.m. 🔄 Last Modified: Dec. 16, 2025, 1:02 p.m.

8.6

CVSS4.0

CVE-2025-65076 - Arbitrary File Read and Delete via Path Traversal in WaveStore Server

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in the ilog script. This script is being run with root privile…

📅 Published: Dec. 16, 2025, 12:25 p.m. 🔄 Last Modified: Dec. 16, 2025, 12:25 p.m.

5.1

CVSS4.0

CVE-2025-65075 - Arbitrary File Read and Delete via Path Traversal in WaveStore Server

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions of dvr user, on the server using path traversal in the alog script. This issu…

📅 Published: Dec. 16, 2025, 12:25 p.m. 🔄 Last Modified: Dec. 16, 2025, 12:25 p.m.

8.6

CVSS4.0

CVE-2025-65074 - OS Command Injection via Path Traversal in WaveStore Server

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version …

📅 Published: Dec. 16, 2025, 12:25 p.m. 🔄 Last Modified: Dec. 16, 2025, 12:25 p.m.

8.5

CVSS3.1

CVE-2025-14443 - Ose-openshift-apiserver: openshift api server: server-side request forgery (ssrf) vulnerability in …

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when proces…

📅 Published: Dec. 16, 2025, 12:14 p.m. 🔄 Last Modified: Dec. 16, 2025, 12:14 p.m.

7.5

CVSS3.1

CVE-2025-13474 - IDOR in Menulux Software's Mobile App

Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers.This issue affects Mobile App: before 9.5.8.

📅 Published: Dec. 16, 2025, 11:25 a.m. 🔄 Last Modified: Dec. 16, 2025, 11:25 a.m.

4.3

CVSS3.1

CVE-2025-13741 - Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Cat…

The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getAuthors function in all versions up to, and including, 4.9.2. This makes it po…

📅 Published: Dec. 16, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 16, 2025, 11:15 a.m.

6.4

CVSS3.1

CVE-2025-11220 - Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text …

The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authentica…

📅 Published: Dec. 16, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 16, 2025, 11:15 a.m.

5.3

CVSS4.0

CVE-2025-0836 - XProtect MIP API Missing Authorization

Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.

📅 Published: Dec. 16, 2025, 11:02 a.m. 🔄 Last Modified: Dec. 16, 2025, 11:02 a.m.
Total resulsts: 322815
Page 26 of 32,282
« previous page » next page
Filters