5.3

CVSS3.1

CVE-2025-56009 -

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 1:09 p.m.

6.5

CVSS3.1

CVE-2025-61464 -

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 30, 2025, 4:46 p.m.

6.1

CVSS3.1

CVE-2025-60837 -

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 8:13 p.m.

6.1

CVSS3.1

CVE-2025-60859 -

Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:36 a.m.

6.5

CVSS3.1

CVE-2025-56007 -

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 1:10 p.m.

6.5

CVSS3.1

CVE-2025-50949 - fontforge: Fontforge memory leak

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 8:18 p.m.

5.9

CVSS3.1

CVE-2025-62813 - lz4: LZ4 null handling error

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 29, 2025, 6:15 a.m.

4.9

CVSS3.1

CVE-2025-62820 -

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 1:20 p.m.

6.5

CVSS3.1

CVE-2025-50951 - fontforge: Fontforge memory leak

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 8:17 p.m.

5.4

CVSS3.1

CVE-2025-12110 - Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offlโ€ฆ

A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes the scope, and assuโ€ฆ

๐Ÿ“… Published: Oct. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 20, 2026, 9:04 p.m.
Total resulsts: 343921
Page 2782 of 34,393
ยซ previous page ยป next page
Filters