4.9

CVSS3.1

CVE-2025-66625 - Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functiโ€ฆ

Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The applicationโ€™s error responses (HTTP 500 โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 8:09 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 9:27 p.m.

7.5

CVSS4.0

CVE-2025-66457 - Elysia affected by arbitrary code injection through cookie config

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are subject to arbitrary code execution from cookie config. When dynamic cookies are enabled (e.g. there an existing cookie schema), the cookie โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 2:27 p.m.

9.1

CVSS4.0

CVE-2025-66456 - Elysia vulnerable to prototype pollution with multiple standalone schema validation

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due toโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 7:43 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 2:30 p.m.

7

CVSS3.1

CVE-2025-66214 - Ladybug has an XMLDecoder Deserialization Vulnerability (Java RCE)

Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the APIs /iaf/ladybug/api/report/{storage} and /iaf/ladybug/api/report/upload, which allow uploading gzip-compressed XML files with user-controllable contenโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 7:37 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 2:32 p.m.

6.9

CVSS4.0

CVE-2025-14337 - itsourcecode Student Management System new_grade.php sql injection

A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulation of the argument grade causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

๐Ÿ“… Published: Dec. 9, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 8:09 p.m.

9.3

CVSS4.0

CVE-2025-64113 - Emby Server allows attackers to gain administrative server access without preconditions

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 7:21 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:58 p.m.

6.9

CVSS4.0

CVE-2025-14336 - itsourcecode Student Management System promote.php sql injection

A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.php. The manipulation of the argument sy results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and coโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 1:58 p.m.

6.9

CVSS4.0

CVE-2025-14335 - itsourcecode Student Management System new_school_year.php sql injection

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /new_school_year.php. The manipulation of the argument sy leads to sql injection. It is possible to initiate the attack remotely. The exploit has beenโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 1:59 p.m.

6.5

CVSS3.1

CVE-2025-9613 - CVE-2025-9613

A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completiโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 6:52 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:43 p.m.

6.5

CVSS3.1

CVE-2025-9614 - CVE-2025-9614

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead tโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 6:48 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:44 p.m.
Total resulsts: 349182
Page 2704 of 34,919
ยซ previous page ยป next page
Filters