9.8

CVSS3.1

CVE-2025-63694 -

DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 7:16 p.m.

6.1

CVSS3.1

CVE-2025-56526 -

Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 7:35 p.m.

6.5

CVSS3.1

CVE-2025-63513 -

kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 9:57 p.m.

10

CVSS3.1

CVE-2025-63216 -

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 9:54 p.m.

7.5

CVSS3.1

CVE-2025-56527 -

Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 7:37 p.m.

7.5

CVSS3.1

CVE-2025-55796 -

The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are generated by hashing the current timestamp formatted as…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:05 p.m.

9.8

CVSS3.1

CVE-2025-54321 -

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 7 p.m.

5.3

CVSS3.1

CVE-2025-63829 -

eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:09 a.m.

6.5

CVSS3.1

CVE-2025-63603 -

A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute user-supplied scripts but fails to restrict the __builtins__ dict…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 8:38 p.m.

4.8

CVSS3.1

CVE-2025-61661 - Grub2: grub2: out-of-bounds write via malicious usb device

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a malicious…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346565
Page 2725 of 34,657
Β« previous page Β» next page
Filters