7.4

CVSS3.1

CVE-2025-65291 -

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 5:04 p.m.

8.4

CVSS3.1

CVE-2025-65807 -

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:20 p.m.

7.5

CVSS3.1

CVE-2025-65512 -

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to in…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:03 p.m.

5.4

CVSS3.1

CVE-2025-67502 - Taguette does not safeguard against Open Redirect

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP redirects without any…

πŸ“… Published: Dec. 9, 2025, 11:53 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:11 p.m.

9.4

CVSS4.0

CVE-2025-67501 - WeGIA is vulnerable to SQL Injection via editar_categoria endpoint parameter

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vulnerability in the /html/matPat/editar_categoria.php endpoint. The application fails to properly validate and sanitize user inputs in the id_categoria …

πŸ“… Published: Dec. 9, 2025, 11:49 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 8:12 p.m.

3.7

CVSS3.1

CVE-2025-67500 - Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking whether a given status exists by sending a request wit…

πŸ“… Published: Dec. 9, 2025, 11:44 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 3:18 p.m.

9.1

CVSS3.1

CVE-2025-61808 - ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and scope is changed.

πŸ“… Published: Dec. 9, 2025, 11:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

8.2

CVSS3.1

CVE-2025-61813 - ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation o…

πŸ“… Published: Dec. 9, 2025, 11:41 p.m. πŸ”„ Last Modified: April 28, 2026, 2:23 a.m.

8.4

CVSS3.1

CVE-2025-61812 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.

πŸ“… Published: Dec. 9, 2025, 11:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

6.8

CVSS3.1

CVE-2025-61821 - ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Explo…

πŸ“… Published: Dec. 9, 2025, 11:41 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 6:51 p.m.
Total resulsts: 349182
Page 2698 of 34,919
Β« previous page Β» next page
Filters