5.3

CVSS3.1

CVE-2025-12994 -

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.

๐Ÿ“… Published: Dec. 4, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 6:10 p.m.

8.5

CVSS3.1

CVE-2025-65958 - Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1โ€ฆ

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to acโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 7:55 p.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 3:18 p.m.

8.7

CVSS4.0

CVE-2025-12097 - Relative Path Traversal Vulnerability in NI System Web Server

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ย Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. ย This vulnerability eโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 7:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-65945 - auth0/node-jws improper HMAC signature verification vulnerability

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:45 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 9:19 p.m.

5.3

CVSS4.0

CVE-2025-14016 - macrozheng mall-swarm delete improper authorization

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publiclโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 3:44 p.m.

8.7

CVSS4.0

CVE-2025-14015 - H3C Magic B0 aspForm EditWlanMacList buffer overflow

A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and cโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 12:27 a.m.

5.1

CVSS4.0

CVE-2025-13488 - Nexus Repository 3 - Stored Cross-Site Scripting (XSS)

Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user conteโ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:16 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-14013 - JIZHICMS Comment addcomment.html cross site scripting

A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/admins/Comment/addcomment.html of the component Comment Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated remotely. The โ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 6:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 5:40 a.m.

8.4

CVSS4.0

CVE-2025-9127 - PX Enterprise Improper Sanitization Vulnerability

A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

๐Ÿ“… Published: Dec. 4, 2025, 5:59 p.m. ๐Ÿ”„ Last Modified: Feb. 3, 2026, 4:57 p.m.

5.1

CVSS4.0

CVE-2025-14012 - JIZHICMS Batch Delete Comments deleteAll.html delete sql injection

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely.โ€ฆ

๐Ÿ“… Published: Dec. 4, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.
Total resulsts: 347773
Page 2680 of 34,778
ยซ previous page ยป next page
Filters