4.3

CVSS3.1

CVE-2025-64898 - ColdFusion | Insufficiently Protected Credentials (CWE-522)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmiโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

8.4

CVSS3.1

CVE-2025-61810 - ColdFusion | Deserialization of Untrusted Data (CWE-502)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted sโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

9.1

CVSS3.1

CVE-2025-61809 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 7:04 p.m.

6.2

CVSS3.1

CVE-2025-61822 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system. Exploitation of this iโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 7:58 p.m.

5.6

CVSS3.1

CVE-2025-64897 - ColdFusion | Improper Access Control (CWE-284)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitatโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

6.2

CVSS3.1

CVE-2025-61823 - ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on thโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 6:42 p.m.

9.1

CVSS3.1

CVE-2025-61811 - ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute maโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

6.6

CVSS3.1

CVE-2025-67499 - CNI Plugins Portmap nftables backend intercepts non-local traffic

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the nftables backend, thus igโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 11:13 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2025-67496 - WeGia is Vulnerable to XSS through id_pessoa Parameter on Password Configuration Page

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 10:43 p.m. ๐Ÿ”„ Last Modified: Dec. 18, 2025, 8:08 p.m.

8

CVSS3.1

CVE-2025-67495 - ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login

ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticateโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 10:38 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 6:30 p.m.
Total resulsts: 349182
Page 2699 of 34,919
ยซ previous page ยป next page
Filters