8.3

CVSS3.1

CVE-2024-44599 -

FNT Command 13.4.0 is vulnerable to Directory Traversal.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:06 p.m.

7.5

CVSS3.1

CVE-2025-65779 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:39 a.m.

8.8

CVSS3.1

CVE-2025-65780 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privileg…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:37 a.m.

6.2

CVSS3.1

CVE-2025-65835 -

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_CO…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 8:57 p.m.

2.5

CVSS3.1

CVE-2025-55703 -

An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outdated API endpoint that applied arrays without proper input validation. This can allow attackers to manipulate SQL queries. This has been addressed in Power IQ version 9.2.1, where…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 8:28 p.m.

8.7

CVSS3.1

CVE-2025-11393 - Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allo…

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allow…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-66439 -

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the fr…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:21 p.m.

6.1

CVSS3.1

CVE-2025-51962 -

A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:43 p.m.

9.1

CVSS3.1

CVE-2025-55895 -

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:21 p.m.

5.3

CVSS3.1

CVE-2023-38913 -

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:33 p.m.
Total resulsts: 349182
Page 2612 of 34,919
Β« previous page Β» next page
Filters